Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

June 2024 VRT update #532

Merged
merged 3 commits into from
Jul 4, 2024
Merged

June 2024 VRT update #532

merged 3 commits into from
Jul 4, 2024

Conversation

RRudder
Copy link
Contributor

@RRudder RRudder commented Jun 18, 2024

Added:

  • P5: Server Security Misconfiguration - Email verification bypass
  • P5: Server Security Misconfiguration - Missing Subresource Integrity (SRI)
  • Varies: Server Security Misconfiguration - Software Package Takeover
  • P5: Sensitive Data Exposure - Token Leakage via Referer - Password Reset Token
  • Varies: Broken Access Control (BAC) - Privilege Escalation

Removed:

  • Varies: Broken Authentication and Session Management - Privilege Escalation

RRudder added 3 commits June 13, 2024 18:01
* Privilege Escalation via Broken Authentication
## To Be Added:
-  P5: Server Security Misconfiguration - Email verification bypass
- P5: Server Security Misconfiguration - Missing Subresource Integrity (SRI)
- Varies: Server Security Misconfiguration - Software Package Takeover
- P5: Sensitive Data Exposure - Token Leakage via Referer - Password Reset Token
- Varies: Broken Access Control (BAC) - Privilege Escalation

## To Be Removed:
- Varies: Broken Authentication and Session Management - Privilege Escalation
@RRudder RRudder requested a review from nnons June 28, 2024 08:04
Copy link
Contributor

@nnons nnons left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@RRudder RRudder merged commit 52dc732 into master Jul 4, 2024
3 checks passed
@RRudder RRudder deleted the June-2024-VRT-Update branch July 4, 2024 03:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants