Commit d2e1fa1
committed
ascanrulesBeta: Address ReDoS in Insecure HTTP Methods rule
- CHANGELOG > Add fix note.
- InsecureHttpMethodScanRule > Adjust regex pattern for Google title
elements. There's no reason to look for unlimited length character
strings. It is doubtful that google would produce content that might
cause a ReDoS, but limiting the regex is "safest".
Signed-off-by: kingthorin <[email protected]>
# Conflicts:
# addOns/ascanrulesBeta/CHANGELOG.md1 parent e7829b1 commit d2e1fa1
File tree
2 files changed
+4
-1
lines changed- addOns/ascanrulesBeta
- src/main/java/org/zaproxy/zap/extension/ascanrulesBeta
2 files changed
+4
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
10 | 13 | | |
11 | 14 | | |
12 | 15 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
149 | 149 | | |
150 | 150 | | |
151 | 151 | | |
152 | | - | |
| 152 | + | |
153 | 153 | | |
154 | 154 | | |
155 | 155 | | |
| |||
0 commit comments