OWASP Top 10 là danh sách 10 nhóm rủi ro bảo mật web nghiêm trọng nhất, cập nhật định kỳ — dùng làm khung tối thiểu để rà soát ứng dụng. Vài mục cốt lõi:
- Broken Access Control: kiểm quyền thiếu/sai → user thấy/sửa dữ liệu người khác. Thường đứng đầu.
- Cryptographic Failures: bảo vệ dữ liệu nhạy cảm kém (không TLS, hash mật khẩu yếu).
- Injection: SQL/command/LDAP injection — dữ liệu bị hiểu thành lệnh (dùng query tham số hóa).
- Insecure Design, Security Misconfiguration, Vulnerable Components (thư viện có CVE), Identification/Auth Failures, SSRF...
Secrets management (liên quan Cryptographic/Misconfiguration): không hardcode API key/DB password/token trong code hay commit vào Git. Đưa vào biến môi trường hoặc secret manager (Vault, AWS Secrets Manager, Vercel env); phân quyền tối thiểu, rotate định kỳ, và tách secret theo môi trường (dev/prod).