alipay / ant-application-security-testing-benchmark

xAST评价体系,让安全工具不再“黑盒”. The xAST evaluation benchmark makes security tools no longer a "black box".
https://xastbenchmark.github.io
Apache License 2.0
323 stars 40 forks source link

Confusion of DAST BS00104 #34

Closed osxtest closed 4 months ago

osxtest commented 8 months ago

Hi, I think that LTAeLQ1K2EaTgNkk in BS00104Controller.java is not the standard format of Aliyun access key. Therefore, I'm unsure if this should be considered as an access key leakage.

https://github.com/alipay/ant-application-security-testing-benchmark/blob/885cde0d8b6c860c3eabbb241e2e6544804a494b/dast-java/src/main/java/com/alipay/antbenchmark/controller/bs/BS00104Controller.java#L26

However, the scorecard for BS00104 categorizes this as a vulnerability.

https://github.com/alipay/ant-application-security-testing-benchmark/blob/885cde0d8b6c860c3eabbb241e2e6544804a494b/dast-java/src/main/resources/scorecard/BS00104.yaml#L4

Could you please clarify which one is the expected behavior? Thank you.

yulailailailai commented 4 months ago

Hello, thank you for discovering the bug. We have modified the Aliyun access key in DAST shooting range /sensitive/BS00104 to comply with the specifications