Security
Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
Here are 1,099 public repositories matching this topic...
-
Updated
Nov 24, 2020 - Java
-
Updated
Oct 11, 2019 - Java
-
Updated
Nov 26, 2020 - Java
-
Updated
Nov 26, 2020 - Java
-
Updated
Nov 25, 2020 - Java
-
Updated
Nov 1, 2020 - Java
Description
BeanUtils is a library that is doing automatic mapping to Java object.
It can cause arm when the attack controls part of the list of properties being sets. BeanUtils does not blacklist properties like class, classloader or other objects that are likely to load arbitrary classes and possibly run code.
Code
import org.apache.commons.beanutils.BeanUtils;
public-
Updated
Jul 23, 2020 - Java
Summary
Dependabot has identified several security vulnerabilities in the 3rd party libraries Pacbot relies on. In most cases, these vulnerabilities can be resolved by upgrading the library to the most current version.
Maintainers, if you're internal to T-Mobile, you should have been seeing these security alerts coming in over the last several weeks. *Please respond to these in a timely ma
-
Updated
Nov 26, 2020 - Java
-
Updated
Nov 25, 2020 - Java
The current swagger definition is autogenerated. The automatically generated definitions rely on reflection and annotations to create the documentation. The reflection capabilities are poor at best and lead to missing API parameters. Annotations can help in some cases, but the only fix for Swagger is to create individual POJOs for every possible request. This will lead to unnecessary large number
-
Updated
Jul 1, 2020 - Java
-
Updated
Oct 28, 2020 - Java
-
Updated
Apr 24, 2019 - Java
-
Updated
Nov 16, 2020 - Java
-
Updated
Oct 8, 2020 - Java
-
Updated
Oct 13, 2020 - Java
-
Updated
Nov 26, 2020 - Java
-
Updated
Dec 12, 2018 - Java
-
Updated
Nov 23, 2020 - Java
- Wikipedia
- Wikipedia
Security apps
Sonatype DepShield
Monitor your open source components for security vulnerabilities - goodbye muda, hello kaizen
Snyk
Find, fix (and prevent!) known vulnerabilities in your code
GuardRails
GuardRails provides continuous security feedback for modern development teams
WhiteSource Bolt
Detect open source vulnerabilities in real time with suggested fixes for quick remediation
BackHub
Reliable GitHub repository backup, set up in minutes
LGTM
Find and prevent zero-days and other critical bugs, with customizable alerts and automated code review
Dependabot Preview
Automated dependency updates for Ruby, JavaScript, Python, Go, PHP, Elixir, Rust, Java and .NET
Renovate
Keep dependencies up-to-date with automated Pull Requests

Background:
This is logged on the back of the discussion with the ZAP team about the current behaviour of XML External Entity Attack scanner. There were two concerns raised in this discussion. I am creating seperate tickets for them as they can be addressed independent of each other. F