Bearer / bearer

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
https://docs.bearer.com
Other
2.05k stars 105 forks source link

Underreporting of framework vulnerabilities (Think framework) #1694

Open pyroxenites opened 1 month ago

pyroxenites commented 1 month ago

When I use the tool to perform a scan, I found that if the user-inputted parameters originate from the framework’s request parameters, the bearer will ignore this vulnerability.

image
didroe commented 1 month ago

Unfortunately we don't currently support the Think framework, only Symfony.

It's not something we have on our roadmap at the moment I'm afraid, but I'll leave this open as a feature request and we'll update you if that changes.