ascanrules: Address SSTI false positive
Overview
- CHANGELOG > Fix note
- SstiScanRule > Adjust logic to prevent False Positives.
- SstiScanRuleUnitTest > Updated for adjusted logic.
Related Issues
- Fixes zaproxy/zaproxy#8622
Checklist
- [na] Update help
- [x] Update changelog
- [x] Run
./gradlew spotlessApplyfor code formatting - [x] Write tests
- [x] Check code coverage
- [x] Sign-off commits
- [x] Squash commits
- [x] Use a descriptive title
Have you tested this against the "Websites Vulnerable to SSTI" app?
Yup, sorry I meant to mention that. Yes I did grab the docker image and test before/after. Everything is still found that was originally.
Tweaked and de-conflicted.
Would love to see this merged. This is something we're still seeing quite frequently, and it looks like @kingthorin has done the work to solve it.
Pending comments and needs rebase.
Checkmarx One – Scan Summary & Details – 7754e854-a0df-4e0a-af58-c7c2c15b9a8a
Fixed Issues
| Severity | Issue | Source File / Package |
|---|---|---|
![]() |
Cx89601373-08db | Npm-debug-3.2.7 |
![]() |
Cx89601373-08db | Npm-debug-2.6.9 |
Thank you!
@psiinon do you want to check again?
