obiba / agate

OBiBa's user ID provider.
GNU General Public License v3.0
4 stars 7 forks source link

Tenable Scan Warning - Blind NoSQL Injection (differential analysis) #502

Closed jonathanmassehsj closed 1 year ago

jonathanmassehsj commented 1 year ago

image

ymarcon commented 1 year ago

Please provide an example with curl.

jonathanmassehsj commented 1 year ago

I investigated more in details.

I think it's a false positive because the web page is displaying Authentication failed. Please verify credentials. with the same parameters.

I think maybe it's because it's receive an HTTP 200 and the scanner think it worked.

I will close this ticket because I don't think there is an issue there.

jonathanmassehsj commented 1 year ago

Many thanks @ymarcon