-
Notifications
You must be signed in to change notification settings - Fork 190
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
rules:feat - adding rule to spring framework rce
This commit adds a new rule to identify a new remote code execution vulnerability in the spring framework. Due to the limitations of the regex engine, this rule can bring some false positives about safe versions pointed out as vulnerabilities. The rule will consider any vulnerability < 5.3.18 as vulnerable, which is not true, as versions >= 5.2.20 already have the fix for the problem, but due to the limitation of the engine we can't detect it. Signed-off-by: Nathan Martins <nathan.martins@zup.com.br>
- Loading branch information
1 parent
6fa62e4
commit bff71b0
Showing
5 changed files
with
132 additions
and
3 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters