close
The Wayback Machine - https://web.archive.org/web/20200908021659/https://github.com/github/securitylab/issues/137/
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[JAVA] CWE-706: Use of Incorrectly-Resolved Name or Reference & CWE-201: Exposure of Sensitive Information Through Sent Data #137

Open
intrigus-lgtm opened this issue Jun 24, 2020 · 1 comment

Comments

@intrigus-lgtm
Copy link

@intrigus-lgtm intrigus-lgtm commented Jun 24, 2020

CVE ID(s)

List the CVE ID(s) associated with this vulnerability. GitHub will automatically link CVE IDs to the GitHub Advisory Database.

Report

Paths that can be influenced by users (= Directory traversal) where the content of the path is returned to the user or where user data is written to.
"Arbitrary read and write"
Query: github/codeql#3794

  • Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc). We would love to have you spread the word about the good work you are doing
@anticomputer
Copy link
Contributor

@anticomputer anticomputer commented Jul 15, 2020

@intrigus-lgtm as per https://securitylab.github.com/bounties this submission in the Bug Slayer category will require at least 4 CVE to be triaged as a direct result of this query's findings. We understand this is still a work in progress, so please update this issue when your CVE listings start coming in and we'll move the award evaluation process along accordingly. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
2 participants
You can’t perform that action at this time.