Skip to content

Commit 74492fe

Browse files
committed
Close issue #538 addressing CVE-2019-17571 with security bulletin.
1 parent 422ba9f commit 74492fe

File tree

3 files changed

+8
-0
lines changed

3 files changed

+8
-0
lines changed

SECURITY.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,3 +40,11 @@ can understand what needs to be done to fix it. Unfortunately at this time, we
4040
are not in a position to pay out bug bounties for vulnerabilities.
4141

4242
Eventually, we would like to have BugCrowd handle this, but that's still a ways off.
43+
44+
## Security Bulletins
45+
46+
There are some ESAPI security bulletins published in the "documentation" directory on GitHub.
47+
For details see:
48+
49+
* (Security Bulletin #1 - MAC Bypass in ESAPI Symmetric Encryption)[documentation/ESAPI-security-bulletin1.pdf], which covers CVE-2013-5679 and CVE-2013-5960
50+
* (Security Bulletin #2 - How Does CVE-2019-17571 Impact ESAPI?)[documentation/ESAPI-security-bulletin2.pdf], which covers the Log4J 1 deserialization CVE.
31.2 KB
Binary file not shown.
101 KB
Binary file not shown.

0 commit comments

Comments
 (0)