google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

Modify CVE-2023-1177 to cover CVE-2023-6977 #493

Closed frkngksl closed 3 weeks ago

frkngksl commented 1 month ago

Hi @tooryx ,

This is the modification that resolves #450

Vulnerable and Fixed Environments are here: https://github.com/google/security-testbeds/pull/61

tooryx commented 3 weeks ago

Thank you @frkngksl, this looks good overall. I will take some time to test it soon.

~tooryx

frkngksl commented 3 weeks ago

Thanks a lot @tooryx !

tooryx commented 3 weeks ago

Could you please fill the relatedId field with all three CVEs? Here is an example

frkngksl commented 3 weeks ago

Could you please fill the relatedId field with all three CVEs? Here is an example

Done @tooryx !

tooryx commented 3 weeks ago

Could you please fill the relatedId field with all three CVEs? Here is an example

Done @tooryx !

Thank you! Although, you need to add the 3 of them. This field should contain ALL related CVEs

frkngksl commented 3 weeks ago

@tooryx , so sorry for that, I thought it was already included since it is the main CVE. Sent the commit

tooryx commented 3 weeks ago

Looks good, thanks. I expect it should be merged next week.

frkngksl commented 3 weeks ago

Thanks for all your reviews!

tooryx commented 3 weeks ago

Hi @frkngksl,

Your PR has been merged. This usually means a reward will be granted. Google will start the internal QC process and the reward amount will be determined based on the quality of the detector report. Please be patient and allow up to a week for the QC process to finish. You'll be notified once the decision is made.

Thanks!

frkngksl commented 1 week ago

Hi @tooryx, is there any update on this?

tooryx commented 1 week ago

We are most likely going to review it this week.

~tooryx