Security Scan
A Security Scan provider (Type: Security Scan) probes one or more web targets, fingerprints the software they run (product, vendor, version), and reports the known vulnerabilities (CVEs) that match. Fingerprints and CVEs come from an online data source, so the scan reflects an up-to-date list without upgrading Casdoor.
Configure the provider
-
Go to Providers → Add.
-
Set Category to Scan and Type to Security Scan.
-
Choose a Sub-type — it decides where the scan targets come from:
Sub-type Targets Site The Sites configured in the same organization. Casdoor derives the base URLs from each Site and scans them. Url An explicit list of URLs you enter in the URL field. -
Fill in the fields below and Save.
| Campo | Applies to | Descrição |
|---|---|---|
| Online list | Both | Optional URL of an extra CVE / fingerprint data source (JSON). It is merged on top of the built-in list, so you can add your own signatures. Leave empty to use only the built-in list. |
| URL | Url sub-type only | One or more target URLs, one per line (for example https://example.com). Required for a Url scan. |
Data source
Casdoor always loads its built-in CVE and fingerprint list from https://casdoor.ai/casdoor-data/data.json, and merges any Online list source on top of it. If a source cannot be reached, the scan continues with whatever list was already loaded.