-
Type:
Bug
-
Status: Rejected
-
Priority:
Medium
-
Resolution: Cancelled
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: None
-
Labels:None
-
Environment:Stage
-
Bug Type:Functional
-
Bug Severity:Medium
-
Level:Employee
-
Module:Platform - Security
-
Reported by:Harbinger
-
Item State:Development - On Hold
[Security] [ZAP-Active Scan Alert] Format String Error reported for LanguageName parameter.
Description
A Format String error occurs when the submitted data of an input string is evaluated as a command by the application.
URL : https://stage.workterra.net/Platform/
Method : POST
Parameter :
LanguageName
Attack :
ZAP%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s
Solution :
Rewrite the background program using proper deletion of bad character strings. This will require a recompile of the background executable.
Other information :
Potential Format String Error. The script closed the connection on a /%s
Please refer attached HTML report for more details.
CC : Rakesh RoySachin HingoleHrishikesh DeshpandeSamirVijayendra ShindeVijay SiddhaBharti SatputeGaurav SodaniNidhi Kaul
- relates to
-
NF-2714 Vulnerability Assessment and Penetration Testing for Workterra on Azure US environment.
-
- To Do
-
Assignee | Satya [ ID10004 ] | Jaideep Vinchurkar [ jaideep.vinchurkar ] |
Assignee | Jaideep Vinchurkar [ jaideep.vinchurkar ] | Akash Thakur [ akash.thakur ] |
Sprint | WT Sprint 37 - Bugs [ 87 ] |
Dev Due Date | 21/Sep/2017 |
-
- Time Spent:
- 2h
-
Analysis of zap active scan vulnerability reported for parameter
Remaining Estimate | 2h [ 7200 ] | 6h [ 21600 ] |
Original Estimate | 2h [ 7200 ] | 6h [ 21600 ] |
-
- Time Spent:
- 4h
-
debugging and trying workaround for format error string issue reported by zap.
Remaining Estimate | 6h [ 21600 ] | 4h [ 14400 ] |
Time Spent | 2h [ 7200 ] | |
Worklog Id | 78949 [ 78949 ] |
Remaining Estimate | 4h [ 14400 ] | 0h [ 0 ] |
Time Spent | 2h [ 7200 ] | 6h [ 21600 ] |
Worklog Id | 78950 [ 78950 ] |
Item State | Parent values: Development(10200)Level 1 values: In Analysis(10204) |
Item State | Parent values: Development(10200)Level 1 values: In Analysis(10204) | Parent values: Development(10200)Level 1 values: On Hold(10207) |
Dev Due Date | 21/Sep/2017 |
Sprint | WT Sprint 37 - Bugs [ 87 ] |
Environment_New | Stage [ 18443 ] |
Time Spent | 6h [ 21600 ] | 10h [ 36000 ] |
Worklog Id | 92072 [ 92072 ] |
Time Spent | 10h [ 36000 ] | 13h [ 46800 ] |
Worklog Id | 92289 [ 92289 ] |
Assignee | Akash Thakur [ akash.thakur ] | Santosh Balid [ santosh.balid ] |
Assignee | Santosh Balid [ santosh.balid ] | Gaurav Sodani [ gaurav.sodani ] |
Assignee | Gaurav Sodani [ gaurav.sodani ] | Prasad Pise [ prasadp ] |
Status | Open [ 1 ] | In Development [ 10007 ] |
Resolution | Cancelled [ 10300 ] | |
Status | In Development [ 10007 ] | Rejected [ 10004 ] |
Link | This issue relates to DEV-13718 [ DEV-13718 ] |
Transition | Time In Source Status | Execution Times |
---|
|
328d 12h 48m | 1 |
|
7s | 1 |
Keeping on hold because of low bandwidth