HXSecurity / DongTai-agent-java

Java Agent is a Java application probe of DongTai IAST, which collects method invocation data during runtime of Java application by dynamic hooks.
https://dongtai.io
Apache License 2.0
682 stars 192 forks source link

[Agent compatibility]: javaweb-vuln靶场中 json来源的漏洞无法检测 #602

Open johnniesong opened 1 year ago

johnniesong commented 1 year ago

Preflight Checklist

Version

1.15.0

Installation Type

Official Docker Compose

Describe the details of the bug and the steps to reproduce it

靶场:https://github.com/javaweb-rasp/javaweb-vuln/tree/master

代码 image

请求: image

未检测到json来源的漏洞、get、post等正常

Additional Information

No response

Logs

No response

allen07sec commented 9 months ago

Thank you for your feedback. This bug cannot be detected and has been fixed. Please use the latest agent