zap-extensions
zap-extensions copied to clipboard
ascanrules: fix false positive in cloud metadata
Overview
This pull request fixes the issue of false positives in the CloudMetadataScanRule plugin. The condition for raising an alert has been improved by adding a method to specifically check for both "ami-id" and "ami-launch-index" in the response body.
Fixes zaproxy/zaproxy#8514
All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.
I have read the CLA Document and I hereby sign the CLA
Changelog should be updated and tests added.
Rebased to address the conflicts and adjust the changelog (move fix entry to latest version).
Thank you!
Checkmarx One – Scan Summary & Details – fb09240f-e0b0-40f5-9dc5-3b9ce8409363