-
Notifications
You must be signed in to change notification settings - Fork 192
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
rules:feat - adding rule to spring framework rce (#1053)
This commit adds a new rule to identify a new remote code execution vulnerability in the spring framework. Due to the limitations of the regex engine, this rule can bring some false positives about safe versions pointed out as vulnerabilities. The rule will consider any vulnerability < 5.3.18 as vulnerable, which is not true, as versions >= 5.2.20 already have the fix for the problem, but due to the limitation of the engine we can't detect it. Signed-off-by: Nathan Martins <nathan.martins@zup.com.br> (cherry picked from commit e5a7fd0)
- Loading branch information
1 parent
763a796
commit 2c11096
Showing
6 changed files
with
133 additions
and
4 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters