Closed github-actions[bot] closed 2 years ago
Site: http://www.zaproxy.org
Site: https://www.zaproxy.org
View the following link to download the report. RunnerID:984757042
Something needs to be tweaked to not post empty results?
Site: http://www.zaproxy.org
Site: https://www.zaproxy.org New Alerts
View the following link to download the report. RunnerID:1196398412
View the following link to download the report. RunnerID:1410452254
View the following link to download the report. RunnerID:1609472728
Does Cacheable HTTPS response count as a valid informational vulnerability ?
No all the information the site serves is public.
Okay thank you what informational bugs do you accept ?
For the BugBounty I can't think of any. The BugCrowd program is more for high impact stuff. For ZAP itself we only payout for RCEs, though we've accepted some other lower impact things like protocol usage, lack or password masking, etc. For the site we've accepted some reports like link/domain squatting. Hope that helps.
Keep in mind what ZAP is and that it's an Open Source project with very limited funds and a small team.
Thank you well i recently sent a informational that was accepted no payout that is totally fine the fact i got accepted and not denied i was grateful.
Remote Code Executions the holy grail of bugs well time to figure it out thank you.
One last question, if found do you accept Path Traversal bugs ?
I guess we'd be concerned if the traversal was outside of the web root. (Well actually GitHub probably would.)
Ex: No we aren't concerned that: www.zaproxy.org/blog/../ works. However, if you can get access to /etc/passwd or something that we don't intend to have web accessible then yes obviously that's an issue.
Okay thank you just wanted to ask RCE only got it.
It's preferable to use the mailing lists (Get in Touch) for these type of queries.
Besides RCE are there any other critical or high bugs that you might be interested in or it just depends on the impact ?
It really depends on impact. RCE is currently the only thing we consistently payout for. As mentioned earlier there are things we accepted but didn't payout for, it just depends on the issue. As @thc202 mentioned if there's more to this discussion it should be moved to the User Group :wink:
Site: https://www.zaproxy.org New Alerts
Content-Type Header Missing [10019] total: 2:
Ignored Alerts
View the following link to download the report. RunnerID:862420546