Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unvalidated redirect not reported if Referer header is the source #5424

Merged

Conversation

jandro996
Copy link
Member

What Does This Do

Not report unvalidated redirect vulnerability if all tainted object ranges have header Referer as source

Motivation

Avoid unvalidated redirect false positives

@jandro996 jandro996 added the comp: asm iast Application Security Management (IAST) label Jun 19, 2023
@jandro996 jandro996 marked this pull request as ready for review June 19, 2023 09:54
@jandro996 jandro996 requested a review from a team June 19, 2023 09:54
@pr-commenter
Copy link

pr-commenter bot commented Jun 21, 2023

Benchmarks

Parameters

Baseline Candidate
commit 1.17.0-SNAPSHOT~e1c159c160 1.16.0-SNAPSHOT~0676a995f4
config baseline candidate
See matching parameters
Baseline Candidate
module Agent Agent
parent None None

Summary

Found 0 performance improvements and 0 performance regressions! Performance is the same for 22 cases.

@jandro996 jandro996 merged commit 4f96084 into master Jun 21, 2023
@jandro996 jandro996 deleted the alejandro.gonzalez/exclude_referer_from_unvalidated_redirect branch June 21, 2023 06:34
@github-actions github-actions bot added this to the 1.17.0 milestone Jun 21, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
comp: asm iast Application Security Management (IAST)
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants