Security
Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.
Here are 1,268 public repositories matching this topic...
-
Updated
Sep 1, 2021 - Java
-
Updated
Oct 11, 2019 - Java
-
Updated
Sep 1, 2021 - Java
-
Updated
Jul 3, 2021 - Java
-
Updated
Aug 31, 2021 - Java
-
Updated
Sep 1, 2021 - Java
Description
BeanUtils is a library that is doing automatic mapping to Java object.
It can cause arm when the attack controls part of the list of properties being sets. BeanUtils does not blacklist properties like class, classloader or other objects that are likely to load arbitrary classes and possibly run code.
Code
import org.apache.commons.beanutils.BeanUtils;
public-
Updated
May 26, 2021 - Java
Summary
Dependabot has identified several security vulnerabilities in the 3rd party libraries Pacbot relies on. In most cases, these vulnerabilities can be resolved by upgrading the library to the most current version.
Maintainers, if you're internal to T-Mobile, you should have been seeing these security alerts coming in over the last several weeks. *Please respond to these in a timely ma
-
Updated
Sep 1, 2021 - Java
-
Updated
Sep 1, 2021 - Java
The current swagger definition is autogenerated. The automatically generated definitions rely on reflection and annotations to create the documentation. The reflection capabilities are poor at best and lead to missing API parameters. Annotations can help in some cases, but the only fix for Swagger is to create individual POJOs for every possible request. This will lead to unnecessary large number
-
Updated
Aug 30, 2021 - Java
-
Updated
Jul 1, 2020 - Java
-
Updated
Dec 11, 2020 - Java
-
Updated
Aug 9, 2021 - Java
-
Updated
Oct 8, 2020 - Java
-
Updated
Sep 1, 2021 - Java
-
Updated
Aug 13, 2021 - Java
-
Updated
Jun 16, 2021 - Java
- Wikipedia
- Wikipedia
Security apps
GuardRails
GuardRails provides continuous security feedback for modern development teams
Sonatype Lift
Lift helps you find and fix your most elusive bugs so you can spend time writing great code, not debugging it
WhiteSource Bolt
Detect open source vulnerabilities in real time with suggested fixes for quick remediation
Cloudback Backup
Backups your GitHub repositories, fast and secure
Renovate
Keep dependencies up-to-date with automated Pull Requests
LGTM
Find and prevent zero-days and other critical bugs, with customizable alerts and automated code review
Snyk
Find, fix (and prevent!) known vulnerabilities in your code
Semgrep
Code scanning at ludicrous speed. Find bugs, apply guardrails across your repos, and get feedback in PRs, Slack, or email
GitProtect.io Backup
Fully manageable, most professional repository and metadata backup and recovery
Sonatype DepShield
Monitor your open source components for security vulnerabilities - goodbye muda, hello kaizen
BackHub Backups by Rewind
Backup your GitHub repos & metadata automatically. Get daily backups that can be restored in seconds – AWS storage available

Hi,
I am getting some XSS Reflected and persistent alerts generated when a .xls or .pdf file contains unsantised XSS injection strings. I do not want to add an alert filter because it is an .asp page that generates these files and so there could be another XSS vulnerability on the page.
I was wondering if the XSS rule could check the Content-Type header and the file identifying line (first