Company
Date Published
Author
Detectify
Word count
214
Language
-
Hacker News points
None

Summary

Detectify regularly updates its security tool every two weeks with new findings, features, and improvements from its security researchers and the Crowdsource ethical hacker community, although specific updates cannot always be publicized due to confidentiality agreements. Recently, the tool has been enhanced with tests for vulnerabilities reported by ethical hackers, including CVE-2019-3799, which involves a directory traversal vulnerability in Spring Cloud Config that allows attackers to read local files, and CVE-2018-19439, an XSS vulnerability in Oracle Secure Global Desktop due to improper escaping of GET-parameters. Additionally, CVE-2011-4367, another directory traversal issue in Apache MyFaces, has been addressed, along with an open redirect vulnerability in the Oracle Discoverer Viewer BI, where a GET-parameter value is used to create redirects. These updates have been integrated into the Detectify scanner to enhance its security coverage.