jaleelsyed / fx-local

0 stars 0 forks source link

log4j_injection on POST:/api/v1/savings-transaction #210

Open jaleelsyed opened 2 years ago

jaleelsyed commented 2 years ago

Title: log4j_injection Vulnerability on POST:/api/v1/savings-transaction Project: Devtest Description:

Assertion Log4j JNDI Lookup remote server invocation validationRisk: log4j_injection Severity: Critical API Endpoint: http://netbanking.apisec.ai:8080/api/v1/savings-transaction Environment: Master Playbook: ApiV1SavingsTransactionPostBodyParamLog4jInjection Researcher: Default

QUICK TIPS

Suggestion: Effort Estimate: null Hrs Wire Logs:

IMPORTANT LINKS

Vulnerability Details: https://developer.apisec.ai/#/app/projects/8a74813e82019c24018201d4468d0224/dashboard/8a74813e82019c24018201db4d901470/details

Project: https://developer.apisec.ai/#/app/projects/8a74813e82019c24018201d4468d0224/dashboard

Environment: https://developer.apisec.ai/#/app/config-environments/projects/8a74813e82019c24018201d4468d0224/environmentList

Scan Dashboard: https://developer.apisec.ai/#/app/projects/8a74813e82019c24018201d4468d0224/profiles/8a74813e82019c24018201d4aefb070a/runs/8a74813e82019c24018201db1de41443

Playbook: https://developer.apisec.ai/#/app/projects/8a74813e82019c24018201d4468d0224/playbooks/ApiV1SavingsTransactionPostBodyParamLog4jInjection

Coverage: https://developer.apisec.ai/#/app/config-categories/projects/8a74813e82019c24018201d4468d0224/categories

Code Sample: https://developer.apisec.ai/#/app/projects/8a74813e82019c24018201d4468d0224/dashboard/8a74813e82019c24018201db4d901470/codesamples

PS: Please contact support@apisec.ai for apisec access and login issues.

--- apisec Bot ---