Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-10524

[Security] [ZAP-Active Scan Alert] Format String Error reported for LanguageName parameter.

    Details

    • Type: Bug
    • Status: Rejected
    • Priority: Medium
    • Resolution: Cancelled
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Environment:
      Stage
    • Bug Type:
      Functional
    • Bug Severity:
      Medium
    • Level:
      Employee
    • Module:
      Platform - Security
    • Reported by:
      Harbinger
    • Item State:
      Development - On Hold

      Description

      [Security] [ZAP-Active Scan Alert] Format String Error reported for LanguageName parameter.

      Description
      A Format String error occurs when the submitted data of an input string is evaluated as a command by the application.

      URL : https://stage.workterra.net/Platform/

      Method : POST

      Parameter :
      LanguageName

      Attack :
      ZAP%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s

      Solution :
      Rewrite the background program using proper deletion of bad character strings. This will require a recompile of the background executable.

      Other information :
      Potential Format String Error. The script closed the connection on a /%s

      Please refer attached HTML report for more details.

      CC : Rakesh RoySachin HingoleHrishikesh DeshpandeSamirVijayendra ShindeVijay SiddhaBharti SatputeGaurav SodaniNidhi Kaul

        Attachments

          Issue Links

            Activity

            prasadp Prasad Pise (Inactive) created issue -
            prasadp Prasad Pise (Inactive) made changes -
            Field Original Value New Value
            Link This issue relates to NF-2714 [ NF-2714 ]
            satyap Satya made changes -
            Assignee Satya [ ID10004 ] Jaideep Vinchurkar [ jaideep.vinchurkar ]
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) made changes -
            Assignee Jaideep Vinchurkar [ jaideep.vinchurkar ] Akash Thakur [ akash.thakur ]
            gaurav.sodani Gaurav Sodani (Inactive) made changes -
            Sprint WT Sprint 37 - Bugs [ 87 ]
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) made changes -
            Dev Due Date 21/Sep/2017
            akash.thakur Akash Thakur (Inactive) logged work - 14/Sep/17 10:28 AM
            • Time Spent:
              2h
               

              Analysis of zap active scan vulnerability reported for parameter

            akash.thakur Akash Thakur (Inactive) made changes -
            Remaining Estimate 2h [ 7200 ] 6h [ 21600 ]
            Original Estimate 2h [ 7200 ] 6h [ 21600 ]
            akash.thakur Akash Thakur (Inactive) logged work - 15/Sep/17 10:29 AM
            • Time Spent:
              4h
               

              debugging and trying workaround for format error string issue reported by zap.

            akash.thakur Akash Thakur (Inactive) made changes -
            Remaining Estimate 6h [ 21600 ] 4h [ 14400 ]
            Time Spent 2h [ 7200 ]
            Worklog Id 78949 [ 78949 ]
            akash.thakur Akash Thakur (Inactive) made changes -
            Remaining Estimate 4h [ 14400 ] 0h [ 0 ]
            Time Spent 2h [ 7200 ] 6h [ 21600 ]
            Worklog Id 78950 [ 78950 ]
            gaurav.sodani Gaurav Sodani (Inactive) made changes -
            Item State Parent values: Development(10200)Level 1 values: In Analysis(10204)
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) made changes -
            Item State Parent values: Development(10200)Level 1 values: In Analysis(10204) Parent values: Development(10200)Level 1 values: On Hold(10207)
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) made changes -
            Dev Due Date 21/Sep/2017
            Hide
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) added a comment -

            Keeping on hold because of low bandwidth

            Show
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) added a comment - Keeping on hold because of low bandwidth
            gaurav.sodani Gaurav Sodani (Inactive) made changes -
            Sprint WT Sprint 37 - Bugs [ 87 ]
            satyap Satya made changes -
            Environment_New Stage [ 18443 ]
            akash.thakur Akash Thakur (Inactive) logged work - 21/Nov/17 10:49 AM
            • Time Spent:
              4h
               

              Analysis & solution scope

            akash.thakur Akash Thakur (Inactive) made changes -
            Time Spent 6h [ 21600 ] 10h [ 36000 ]
            Worklog Id 92072 [ 92072 ]
            akash.thakur Akash Thakur (Inactive) logged work - 23/Nov/17 06:20 AM
            • Time Spent:
              3h
               
              <No comment>
            akash.thakur Akash Thakur (Inactive) made changes -
            Time Spent 10h [ 36000 ] 13h [ 46800 ]
            Worklog Id 92289 [ 92289 ]
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) made changes -
            Assignee Akash Thakur [ akash.thakur ] Santosh Balid [ santosh.balid ]
            Hide
            santosh.balid Santosh Balid (Inactive) added a comment -

            Please plan it in future sprints.

            Cc : Satya, Jaideep Vinchurkar, Bharti Satpute

            Show
            santosh.balid Santosh Balid (Inactive) added a comment - Please plan it in future sprints. Cc : Satya , Jaideep Vinchurkar , Bharti Satpute
            santosh.balid Santosh Balid (Inactive) made changes -
            Assignee Santosh Balid [ santosh.balid ] Gaurav Sodani [ gaurav.sodani ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Assignee Gaurav Sodani [ gaurav.sodani ] Prasad Pise [ prasadp ]
            Prashant.samal Prashant Samal (Inactive) made changes -
            Status Open [ 1 ] In Development [ 10007 ]
            Prashant.samal Prashant Samal (Inactive) made changes -
            Resolution Cancelled [ 10300 ]
            Status In Development [ 10007 ] Rejected [ 10004 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Link This issue relates to DEV-13718 [ DEV-13718 ]
            Transition Time In Source Status Execution Times
            Prashant Samal (Inactive) made transition -
            Open In Development
            328d 12h 48m 1
            Prashant Samal (Inactive) made transition -
            In Development Rejected
            7s 1

              People

              Assignee:
              prasadp Prasad Pise (Inactive)
              Reporter:
              prasadp Prasad Pise (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - 6h Original Estimate - 6h
                  6h
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 13h
                  13h