Skip to content

PRP: Flowable Exposed UI RCE#156

Open
devampkid wants to merge 6 commits intogoogle:mainfrom
devampkid:flowable
Open

PRP: Flowable Exposed UI RCE#156
devampkid wants to merge 6 commits intogoogle:mainfrom
devampkid:flowable

Conversation

@devampkid
Copy link
Contributor

@giacomo-doyensec
Copy link
Contributor

Hi @devampkid,
please update the testbed accordingly to the modifications from google/tsunami-security-scanner-plugins@debc54a. Add a safe setup and relative instruction in the readme file if possible, thanks!

@devampkid
Copy link
Contributor Author

@giacomo-doyensec I forgot to update this testbed; I've updated it now.

…authentication by changing the spring boot security configuration
@devampkid
Copy link
Contributor Author

@robert-doyensec, the setup is done without the need for any proxy.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tooryx is disabling authentication by replacing the spring security configuration or by adding a reverse proxy okay? The original PRP said that authentication was not required, and it is possible to configure this without authentication, but not very easy as with some other services where it's simply editing a configuration value or missing authentication by default. google/tsunami-security-scanner-plugins#675

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants