Veracode Security Labs Champion Level 3 Certificate

The bearer of this certificate earned 300 total points by completing secure coding labs through Veracode Security Labs. Labs are a form of secure code training that involves hands-on-keyboard exercises, where users demonstrate their abilities to exploit and patch code using real applications.
The following labs were completed toward certification:
Lab NameTopic NameLanguagePoints
One ID to Access All Objects OWASP API 1: Broken Object Level Authorization Java10
Redirect Rodeo OWASP 2021 A1: Broken Access Control [DEPRECATED] Java10
Forging User Requests OWASP 2021 A1: Broken Access Control [DEPRECATED] Java10
Retrieval Without Validation OWASP API 7: Server-Side Request Forgery [SSRF] Java10
The Great Referral Quest OWASP API 6: Unrestricted Access to Sensitive Business Flows Java10
Denial of Service OWASP API 4: Unrestricted Resource Consumption Java10
Do You Remember? Beyond OWASP Top 10: Other Web App Risks .NET10
Unprotected Deployments OWASP API 9: Improper Inventory Management Java10
Logging in the API Infrastructure More OWASP Vulnerabilities for APIs Java10
Access and Erasure General Application Security: User Data Privacy NodeJS20
PII Storage General Application Security: User Data Privacy NodeJS10
Informed Consent General Application Security: User Data Privacy NodeJS10
See-through traffic General Application Security: CWE-319 Cleartext Transmission of Sensitive Data NodeJS10
Rectification General Application Security: User Data Privacy NodeJS10
Fix the Sessions OWASP 2021 A1: Broken Access Control [DEPRECATED] Java10
Get there from here OWASP 2021 A10: Server-Side Request Forgery [DEPRECATED] Java10
Know Your Limits Beyond OWASP Top 10: Other Web App Risks Java10
Secrets in the Log OWASP 2021 A1: Broken Access Control [DEPRECATED] Java10
The Importance of Logging and Monitoring More OWASP Vulnerabilities for APIs Java10
Really, really bad passwords OWASP 2021 A7: Identification and Authentication Failures [DEPRECATED] Java10
Hash it, store it, salt - upgrade it OWASP 2021 A7: Identification and Authentication Failures [DEPRECATED] Java10
Slow Down OWASP 2021 A9: Security Logging and Monitoring Failures [DEPRECATED] Java10
Hold the Line OWASP 2021 A9: Security Logging and Monitoring Failures [DEPRECATED] Java10
Making Secure Decisions OWASP 2021 A4: Insecure Design [DEPRECATED] Java10
Loose Lips Sink Servers OWASP 2021 A1: Broken Access Control [DEPRECATED] NodeJS10
Valid Deficit OWASP 2021 A4: Insecure Design [DEPRECATED] .NET10
Authentication Bypass OWASP 2021 A7: Identification and Authentication Failures [DEPRECATED] NodeJS10
Data Portability General Application Security: User Data Privacy NodeJS10
Terrible Password ChallengeOWASP 2021 A7: Identification and Authentication Failures [DEPRECATED] Java10