Giter VIP home page Giter VIP logo

struts-vulnerabilities's People

Contributors

ajagena avatar andymeneely avatar axj2613 avatar bgood12 avatar blh2666 avatar bnk5096 avatar camilo86 avatar chrestopher avatar christopherbanas avatar craftspider avatar crbarber3 avatar cxd3796 avatar devonbagley97 avatar hmeinertrita avatar jake-scali avatar jponicki avatar leonkuhne avatar lindseyferretti avatar lukasyelle avatar matthewschmitt478 avatar mattthyng avatar mll8657 avatar moiseslorap avatar montemoranon avatar natethegr8falk avatar paulgildehaus avatar randallkentbrown avatar renchauret avatar rlb8800 avatar yerngpaii avatar

Stargazers

 avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar

struts-vulnerabilities's Issues

Commit That Are Likely to Have Contributed to a Vulnerability Missed Duration Curation

Description

In the qualitative analysis of archeogit using http-vulnerabilities, we found certain commits that likely contributed to a vulnerability but were not curated as such. The issue is a summary of all such commits for consideration.

  • CVE-2013-1966
    • 3f1f9a133bba5739273ebc1212f067eff1613a0f is a contributing commit. 3f1f9a133bba5739273ebc1212f067eff1613a0f did indeed modify the line that was later modified to fix the vulnerability. As a consequence, it is reasonable to characterize it as a contributing commit.
  • CVE-2014-0113
    • 0efcc08445720822c2c44a5db426c68a48f0c8aa is a contributing commit. 0efcc08445720822c2c44a5db426c68a48f0c8aa did indeed modify the line that we modified to fix the vulnerability. As a consequence, it is reasonable to expect the commit to be characterized as a contributing commit.
  • CVE-2016-4433
    • 86813c1a7214bc002a5d7ce9981a9ef333e27142 is a contributing commit. 86813c1a7214bc002a5d7ce9981a9ef333e27142 did indeed add a method that was modified to add a check in the vulnerability fixing commit.
    • 702738693ce9206f3023903d73094fe1522cb91c is a contributing commit. 702738693ce9206f3023903d73094fe1522cb91c did indeed modify the line that was later modified to fix the vulnerability.
  • CVE-2017-5638
    • c01d3a92db7f71f751a0522912d24bcf4a94a1b0 is a contributing commit. c01d3a92db7f71f751a0522912d24bcf4a94a1b0 added the file along with 3,103 other files that was modified to fix the vulnerability. The lines that were modified when fixing the vulnerability were added by this contributing commit.
  • CVE-2017-9787
    • 8e9f9fb89ff84e3f383d0aef73443af919c271d7 is a contributing commit. 8e9f9fb89ff84e3f383d0aef73443af919c271d7 did indeed modify the code in core/src/main/java/com/opensymphony/xwork2/interceptor/ChainingInterceptor.java that was eventually modified to fix the vulnerability. Furthermore, the commit message of the contributing commit is also indicative of the type of change the commit is contributing and the description of the vulnerability is also on the same functionality.
  • CVE-2017-9804
    • 931df54ab379bf4eb5a625bf05066b8563c3737b is a contributing commit. 931df54ab379bf4eb5a625bf05066b8563c3737b did indeed add the regular expression (DEFAULT_URL_REGEX) which was specifically modified in both commits that fixed the vulnerability.
  • CVE-2017-12611
    • 97f531cee67fb23cd92dceb86f170cd683dfd955 is a contributing commit. Although 97f531cee67fb23cd92dceb86f170cd683dfd955 added comments that were deleted when 5a0f2e1aaf8d420bd74033175e6e459883160487 fixed the vulnerability, there are lines that were added by the contributing commit that had to be modified to fix the vulnerability. As a consequence, it is reasonable to characterize 97f531cee67fb23cd92dceb86f170cd683dfd955 as a contributing commit.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.