You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
there is at least one CVE around, which requie the attacker to have write access to the configuration. Now I saw another one and kind of lost track of it.
Not sure, but if it's not a single CVE but two, would it be possible to add an option to opt out scanning for CVEs, where write access to a configuration file is required?
Checking log4j doesn't help much, if the attacker already has write access to parts of the application.
The text was updated successfully, but these errors were encountered:
Hi,
there is at least one CVE around, which requie the attacker to have write access to the configuration. Now I saw another one and kind of lost track of it.
Not sure, but if it's not a single CVE but two, would it be possible to add an option to opt out scanning for CVEs, where write access to a configuration file is required?
Checking log4j doesn't help much, if the attacker already has write access to parts of the application.
The text was updated successfully, but these errors were encountered: