-
Notifications
You must be signed in to change notification settings - Fork 288
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix progagation for Untrusted Deserialization vulnerability #7374
Fix progagation for Untrusted Deserialization vulnerability #7374
Conversation
BenchmarksStartupParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 47 metrics, 16 unstable metrics. Startup time reports for petclinicgantt
title petclinic - global startup overhead: candidate=1.39.0-SNAPSHOT~c830d6c73b, baseline=1.39.0-SNAPSHOT~594a2a4428
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.055 s) : 0, 1055444
Total [baseline] (10.401 s) : 0, 10400896
Agent [candidate] (1.048 s) : 0, 1048352
Total [candidate] (10.366 s) : 0, 10366407
section appsec
Agent [baseline] (1.174 s) : 0, 1174015
Total [baseline] (10.461 s) : 0, 10461482
Agent [candidate] (1.175 s) : 0, 1175343
Total [candidate] (10.472 s) : 0, 10471691
section iast
Agent [baseline] (1.18 s) : 0, 1180035
Total [baseline] (10.863 s) : 0, 10863477
Agent [candidate] (1.173 s) : 0, 1172716
Total [candidate] (10.855 s) : 0, 10855061
section profiling
Agent [baseline] (1.245 s) : 0, 1244910
Total [baseline] (10.635 s) : 0, 10634931
Agent [candidate] (1.26 s) : 0, 1260380
Total [candidate] (10.678 s) : 0, 10678119
gantt
title petclinic - break down per module: candidate=1.39.0-SNAPSHOT~c830d6c73b, baseline=1.39.0-SNAPSHOT~594a2a4428
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (673.43 ms) : 0, 673430
BytebuddyAgent [candidate] (668.944 ms) : 0, 668944
GlobalTracer [baseline] (308.356 ms) : 0, 308356
GlobalTracer [candidate] (306.292 ms) : 0, 306292
AppSec [baseline] (51.897 ms) : 0, 51897
AppSec [candidate] (51.446 ms) : 0, 51446
Remote Config [baseline] (674.47 µs) : 0, 674
Remote Config [candidate] (657.698 µs) : 0, 658
Telemetry [baseline] (7.573 ms) : 0, 7573
Telemetry [candidate] (7.532 ms) : 0, 7532
section appsec
BytebuddyAgent [baseline] (681.593 ms) : 0, 681593
BytebuddyAgent [candidate] (682.427 ms) : 0, 682427
GlobalTracer [baseline] (301.389 ms) : 0, 301389
GlobalTracer [candidate] (301.06 ms) : 0, 301060
AppSec [baseline] (157.624 ms) : 0, 157624
AppSec [candidate] (157.255 ms) : 0, 157255
Remote Config [baseline] (610.642 µs) : 0, 611
Remote Config [candidate] (612.119 µs) : 0, 612
Telemetry [baseline] (9.078 ms) : 0, 9078
Telemetry [candidate] (9.336 ms) : 0, 9336
IAST [baseline] (20.332 ms) : 0, 20332
IAST [candidate] (22.137 ms) : 0, 22137
section iast
BytebuddyAgent [baseline] (783.763 ms) : 0, 783763
BytebuddyAgent [candidate] (778.427 ms) : 0, 778427
GlobalTracer [baseline] (298.486 ms) : 0, 298486
GlobalTracer [candidate] (295.812 ms) : 0, 295812
AppSec [baseline] (48.858 ms) : 0, 48858
AppSec [candidate] (50.423 ms) : 0, 50423
Remote Config [baseline] (582.242 µs) : 0, 582
Remote Config [candidate] (597.139 µs) : 0, 597
Telemetry [baseline] (8.885 ms) : 0, 8885
Telemetry [candidate] (7.835 ms) : 0, 7835
IAST [baseline] (25.875 ms) : 0, 25875
IAST [candidate] (26.08 ms) : 0, 26080
section profiling
ProfilingAgent [baseline] (94.23 ms) : 0, 94230
ProfilingAgent [candidate] (94.629 ms) : 0, 94629
BytebuddyAgent [baseline] (663.502 ms) : 0, 663502
BytebuddyAgent [candidate] (673.855 ms) : 0, 673855
GlobalTracer [baseline] (389.267 ms) : 0, 389267
GlobalTracer [candidate] (393.291 ms) : 0, 393291
AppSec [baseline] (52.651 ms) : 0, 52651
AppSec [candidate] (52.757 ms) : 0, 52757
Remote Config [baseline] (684.858 µs) : 0, 685
Remote Config [candidate] (688.781 µs) : 0, 689
Telemetry [baseline] (7.37 ms) : 0, 7370
Telemetry [candidate] (7.431 ms) : 0, 7431
Profiling [baseline] (94.255 ms) : 0, 94255
Profiling [candidate] (94.653 ms) : 0, 94653
Startup time reports for insecure-bankgantt
title insecure-bank - global startup overhead: candidate=1.39.0-SNAPSHOT~c830d6c73b, baseline=1.39.0-SNAPSHOT~594a2a4428
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.049 s) : 0, 1048675
Total [baseline] (8.511 s) : 0, 8511493
Agent [candidate] (1.049 s) : 0, 1048955
Total [candidate] (8.507 s) : 0, 8506637
section iast
Agent [baseline] (1.181 s) : 0, 1180880
Total [baseline] (9.005 s) : 0, 9005183
Agent [candidate] (1.19 s) : 0, 1190400
Total [candidate] (9.019 s) : 0, 9018908
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.172 s) : 0, 1172262
Total [baseline] (8.944 s) : 0, 8944393
Agent [candidate] (1.173 s) : 0, 1173427
Total [candidate] (8.962 s) : 0, 8961599
section iast_TELEMETRY_OFF
Agent [baseline] (1.168 s) : 0, 1167820
Total [baseline] (9.014 s) : 0, 9013622
Agent [candidate] (1.169 s) : 0, 1169440
Total [candidate] (8.953 s) : 0, 8953497
gantt
title insecure-bank - break down per module: candidate=1.39.0-SNAPSHOT~c830d6c73b, baseline=1.39.0-SNAPSHOT~594a2a4428
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (668.567 ms) : 0, 668567
BytebuddyAgent [candidate] (669.117 ms) : 0, 669117
GlobalTracer [baseline] (306.699 ms) : 0, 306699
GlobalTracer [candidate] (306.661 ms) : 0, 306661
AppSec [baseline] (51.744 ms) : 0, 51744
AppSec [candidate] (51.568 ms) : 0, 51568
Remote Config [baseline] (679.05 µs) : 0, 679
Remote Config [candidate] (662.102 µs) : 0, 662
Telemetry [baseline] (7.557 ms) : 0, 7557
Telemetry [candidate] (7.476 ms) : 0, 7476
section iast
BytebuddyAgent [baseline] (784.141 ms) : 0, 784141
BytebuddyAgent [candidate] (792.03 ms) : 0, 792030
GlobalTracer [baseline] (298.113 ms) : 0, 298113
GlobalTracer [candidate] (299.88 ms) : 0, 299880
AppSec [baseline] (52.892 ms) : 0, 52892
AppSec [candidate] (50.693 ms) : 0, 50693
IAST [baseline] (23.581 ms) : 0, 23581
IAST [candidate] (25.539 ms) : 0, 25539
Remote Config [baseline] (584.318 µs) : 0, 584
Remote Config [candidate] (597.374 µs) : 0, 597
Telemetry [baseline] (7.999 ms) : 0, 7999
Telemetry [candidate] (7.974 ms) : 0, 7974
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (779.299 ms) : 0, 779299
BytebuddyAgent [candidate] (778.54 ms) : 0, 778540
GlobalTracer [baseline] (296.306 ms) : 0, 296306
GlobalTracer [candidate] (296.781 ms) : 0, 296781
AppSec [baseline] (49.267 ms) : 0, 49267
AppSec [candidate] (49.612 ms) : 0, 49612
IAST [baseline] (22.96 ms) : 0, 22960
IAST [candidate] (25.613 ms) : 0, 25613
Remote Config [baseline] (603.075 µs) : 0, 603
Remote Config [candidate] (594.421 µs) : 0, 594
Telemetry [baseline] (10.357 ms) : 0, 10357
Telemetry [candidate] (8.767 ms) : 0, 8767
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (774.336 ms) : 0, 774336
BytebuddyAgent [candidate] (775.734 ms) : 0, 775734
GlobalTracer [baseline] (296.554 ms) : 0, 296554
GlobalTracer [candidate] (296.107 ms) : 0, 296107
AppSec [baseline] (51.934 ms) : 0, 51934
AppSec [candidate] (53.395 ms) : 0, 53395
IAST [baseline] (23.796 ms) : 0, 23796
IAST [candidate] (21.375 ms) : 0, 21375
Remote Config [baseline] (584.181 µs) : 0, 584
Remote Config [candidate] (580.383 µs) : 0, 580
Telemetry [baseline] (7.143 ms) : 0, 7143
Telemetry [candidate] (8.74 ms) : 0, 8740
LoadParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 10 metrics, 18 unstable metrics. Request duration reports for insecure-bankgantt
title insecure-bank - request duration [CI 0.99] : candidate=1.39.0-SNAPSHOT~c830d6c73b, baseline=1.39.0-SNAPSHOT~594a2a4428
dateFormat X
axisFormat %s
section baseline
no_agent (371.196 µs) : 352, 391
. : milestone, 371,
iast (479.853 µs) : 458, 502
. : milestone, 480,
iast_FULL (545.382 µs) : 523, 567
. : milestone, 545,
iast_GLOBAL (515.173 µs) : 491, 539
. : milestone, 515,
iast_HARDCODED_SECRET_DISABLED (476.391 µs) : 454, 499
. : milestone, 476,
iast_INACTIVE (444.707 µs) : 423, 466
. : milestone, 445,
iast_TELEMETRY_OFF (471.083 µs) : 450, 493
. : milestone, 471,
tracing (442.972 µs) : 422, 464
. : milestone, 443,
section candidate
no_agent (375.341 µs) : 353, 397
. : milestone, 375,
iast (484.466 µs) : 462, 507
. : milestone, 484,
iast_FULL (548.986 µs) : 528, 570
. : milestone, 549,
iast_GLOBAL (501.115 µs) : 479, 523
. : milestone, 501,
iast_HARDCODED_SECRET_DISABLED (473.528 µs) : 451, 496
. : milestone, 474,
iast_INACTIVE (440.033 µs) : 419, 461
. : milestone, 440,
iast_TELEMETRY_OFF (461.879 µs) : 441, 483
. : milestone, 462,
tracing (442.646 µs) : 422, 464
. : milestone, 443,
Request duration reports for petclinicgantt
title petclinic - request duration [CI 0.99] : candidate=1.39.0-SNAPSHOT~c830d6c73b, baseline=1.39.0-SNAPSHOT~594a2a4428
dateFormat X
axisFormat %s
section baseline
no_agent (1.35 ms) : 1331, 1369
. : milestone, 1350,
appsec (1.734 ms) : 1710, 1758
. : milestone, 1734,
appsec_no_iast (1.724 ms) : 1700, 1749
. : milestone, 1724,
iast (1.462 ms) : 1439, 1484
. : milestone, 1462,
profiling (1.483 ms) : 1458, 1507
. : milestone, 1483,
tracing (1.458 ms) : 1433, 1482
. : milestone, 1458,
section candidate
no_agent (1.325 ms) : 1306, 1345
. : milestone, 1325,
appsec (1.718 ms) : 1694, 1743
. : milestone, 1718,
appsec_no_iast (1.714 ms) : 1690, 1739
. : milestone, 1714,
iast (1.477 ms) : 1455, 1500
. : milestone, 1477,
profiling (1.486 ms) : 1461, 1511
. : milestone, 1486,
tracing (1.473 ms) : 1449, 1497
. : milestone, 1473,
DacapoParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 0 unstable metrics. Execution time for tomcatgantt
title tomcat - execution time [CI 0.99] : candidate=1.39.0-SNAPSHOT~c830d6c73b, baseline=1.39.0-SNAPSHOT~594a2a4428
dateFormat X
axisFormat %s
section baseline
no_agent (1.455 ms) : 1443, 1466
. : milestone, 1455,
appsec (2.211 ms) : 2176, 2246
. : milestone, 2211,
iast (1.953 ms) : 1911, 1995
. : milestone, 1953,
iast_GLOBAL (2.005 ms) : 1962, 2048
. : milestone, 2005,
profiling (1.861 ms) : 1825, 1896
. : milestone, 1861,
tracing (1.832 ms) : 1800, 1865
. : milestone, 1832,
section candidate
no_agent (1.457 ms) : 1446, 1469
. : milestone, 1457,
appsec (2.21 ms) : 2175, 2245
. : milestone, 2210,
iast (1.954 ms) : 1912, 1996
. : milestone, 1954,
iast_GLOBAL (2.018 ms) : 1974, 2062
. : milestone, 2018,
profiling (1.851 ms) : 1817, 1885
. : milestone, 1851,
tracing (1.834 ms) : 1801, 1867
. : milestone, 1834,
Execution time for biojavagantt
title biojava - execution time [CI 0.99] : candidate=1.39.0-SNAPSHOT~c830d6c73b, baseline=1.39.0-SNAPSHOT~594a2a4428
dateFormat X
axisFormat %s
section baseline
no_agent (14.755 s) : 14755000, 14755000
. : milestone, 14755000,
appsec (15.329 s) : 15329000, 15329000
. : milestone, 15329000,
iast (18.731 s) : 18731000, 18731000
. : milestone, 18731000,
iast_GLOBAL (17.911 s) : 17911000, 17911000
. : milestone, 17911000,
profiling (15.369 s) : 15369000, 15369000
. : milestone, 15369000,
tracing (14.964 s) : 14964000, 14964000
. : milestone, 14964000,
section candidate
no_agent (15.459 s) : 15459000, 15459000
. : milestone, 15459000,
appsec (15.125 s) : 15125000, 15125000
. : milestone, 15125000,
iast (18.806 s) : 18806000, 18806000
. : milestone, 18806000,
iast_GLOBAL (18.068 s) : 18068000, 18068000
. : milestone, 18068000,
profiling (14.892 s) : 14892000, 14892000
. : milestone, 14892000,
tracing (15.177 s) : 15177000, 15177000
. : milestone, 15177000,
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM!
What Does This Do
This improves the smoke tests and add new instrumentations to ensure the propagation.
Motivation
Improve the propagation and smoke tests for the Untrusted Deserialization
Additional Notes
Contributor Checklist
type:
and (comp:
orinst:
) labels in addition to any usefull labelsclose
,fix
or any linking keywords when referencing an issue.Use
solves
instead, and assign the PR milestone to the issueJira ticket: APPSEC-54157