From 8b3363c7c2ae80ca8c21df43adda53cc9319d1e1 Mon Sep 17 00:00:00 2001 From: Jim Manico Date: Fri, 12 Mar 2021 17:07:22 -0500 Subject: [PATCH] Update 0x20-V12-Files-Resources.md resolving https://github.com/OWASP/ASVS/issues/679 --- 4.0/en/0x20-V12-Files-Resources.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/4.0/en/0x20-V12-Files-Resources.md b/4.0/en/0x20-V12-Files-Resources.md index 380af3adc..15362bcbf 100644 --- a/4.0/en/0x20-V12-Files-Resources.md +++ b/4.0/en/0x20-V12-Files-Resources.md @@ -39,7 +39,7 @@ Although zip bombs are eminently testable using penetration testing techniques, | # | Description | L1 | L2 | L3 | CWE | | :---: | :--- | :---: | :---:| :---: | :---: | | **12.4.1** | Verify that files obtained from untrusted sources are stored outside the web root, with limited permissions, preferably with strong validation. | ✓ | ✓ | ✓ | 922 | -| **12.4.2** | Verify that files obtained from untrusted sources are scanned by antivirus scanners to prevent upload of known malicious content. | ✓ | ✓ | ✓ | 509 | +| **12.4.2** | Verify that files obtained from untrusted sources are scanned by antivirus scanners to prevent upload and serving of known malicious content. | ✓ | ✓ | ✓ | 509 | ## V12.5 File Download Requirements