Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Findings from ZAP Penetration Test of deegree Console #1615

Open
16 tasks
PaulJade opened this issue Dec 1, 2023 · 0 comments
Open
16 tasks

Findings from ZAP Penetration Test of deegree Console #1615

PaulJade opened this issue Dec 1, 2023 · 0 comments
Assignees
Labels
bug error issue and bug (fix) console deegree administration console contributions welcome asking for contribution (time and money sponsor) CVE Common Vulnerabilities and Exposures TMC discussion to be discussed by technical management committee members

Comments

@PaulJade
Copy link

PaulJade commented Dec 1, 2023

Used Software: https://www.zaproxy.org/download/

Findings

  • PII Disclosure
  • Absence of Anti-CSRF Tokens
  • Content Security Policy (CSP) Header Not Set
  • Missing Anti-clickjacking Header
  • Pufferüberlauf
  • Session ID in URL Rewrite
  • Application Error Disclosure
  • Cookie without SameSite Attribute
  • Information Disclosure - Debug Error Messages
  • Referer Exposes Session ID
  • X-Content-Type-Options Header Missing
  • Information Disclosure - Suspicious Comments
  • Loosely Scoped Cookie
  • Modern Web Application
  • Session Management Response Identified
  • User Agent Fuzzer
@tfr42 tfr42 added bug error issue and bug (fix) console deegree administration console CVE Common Vulnerabilities and Exposures labels Dec 1, 2023
@tfr42 tfr42 added this to To do in TMC board (public) via automation Dec 1, 2023
@tfr42 tfr42 added the TMC discussion to be discussed by technical management committee members label Dec 1, 2023
@tfr42 tfr42 added the contributions welcome asking for contribution (time and money sponsor) label Jan 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug error issue and bug (fix) console deegree administration console contributions welcome asking for contribution (time and money sponsor) CVE Common Vulnerabilities and Exposures TMC discussion to be discussed by technical management committee members
2 participants