New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Java] CWE-598: Use of GET Request Method with Sensitive Query Strings #223
Comments
|
Your submission is now in status SecLab review. For information, the evaluation workflow is the following: |
|
@luchua-bc We've had an initial look at the results from your query. It seems that the query is currently flagging everything that comes from a |
|
Thanks @m-y-mo for reviewing this issue. I've committed the change to use |
|
Hi @luchua-bc, the results look better now, but there are still too many FPs caused by the broad |
|
Thanks @pwntester for reviewing this PR. I've made the requested change. Please review. |
|
Your submission is now in status CodeQL review. For information, the evaluation workflow is the following: |
|
Your submission is now in status SecLab finalize. For information, the evaluation workflow is the following: |
|
Your submission is now in status Pay. For information, the evaluation workflow is the following: |
|
Created Hackerone report 1122662 for bounty 282423 : [223] [Java] CWE-598: Use of GET Request Method with Sensitive Query Strings |
|
Your submission is now in status Closed. For information, the evaluation workflow is the following: |
|
Thanks @xcorail for the quick turn-around and the bounty:-) |
luchua-bc commentedDec 26, 2020
•
edited
CVE ID(s)
List the CVE ID(s) associated with this vulnerability. GitHub will automatically link CVE IDs to the GitHub Advisory Database.
Report
Describe the vulnerability. Provide any information you think will help GitHub assess the impact your query has on the open source community.
When an application uses the GET method to submit sensitive information such as passwords and access tokens, it is transmitted within the query string of the requested URL. Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referer header when any off-site links are followed. Placing passwords into the URL therefore increases the risk that they will be captured by an attacker.
This kind of vulnerabilities is categorized as CWE-598: Use of GET Request Method with Sensitive Query Strings.
This query detects GET requests with sensitive information handled by Java EE Servlets.
Relevant PR is PR# 4880
Result(s)
Provide at least one useful result found by your query, on some revision of a real project.
The text was updated successfully, but these errors were encountered: