Skip to content

Alibaba Cloud Linux 3 Security Advisory#12465

Merged
Maffooch merged 1 commit into
DefectDojo:bugfixfrom
manuel-sommer:alibabacloudlinux3
May 22, 2025
Merged

Alibaba Cloud Linux 3 Security Advisory#12465
Maffooch merged 1 commit into
DefectDojo:bugfixfrom
manuel-sommer:alibabacloudlinux3

Conversation

@manuel-sommer

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot added settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR ui labels May 16, 2025
@dryrunsecurity

dryrunsecurity Bot commented May 16, 2025

Copy link
Copy Markdown

DryRun Security

🔴 Risk threshold exceeded.

This pull request contains a sensitive edit to the file dojo/templatetags/display_tags.py and includes a potential information disclosure risk in the settings file related to hardcoded CVE URLs.

⚠️ Configured Codepaths Edit in dojo/templatetags/display_tags.py
Vulnerability Configured Codepaths Edit
Description Sensitive edits detected for this file. Sensitive file paths and allowed authors can be configured in .dryrunsecurity.yaml.
💭 Unconfirmed Findings (1)
Vulnerability Potential Information Disclosure URL
Description In the file dojo/settings/settings.dist.py, hardcoded URLs for Alibaba Linux 3 CVE information could potentially leak internal infrastructure or security tracking details, presenting a minor information disclosure risk.

We've notified @mtesauro.


All finding details can be found in the DryRun Security Dashboard.

mtesauro
mtesauro previously approved these changes May 18, 2025
@mtesauro mtesauro dismissed their stale review May 18, 2025 02:53

Clicked too quick

@Maffooch Maffooch added this to the 2.46.4 milestone May 20, 2025

@mtesauro mtesauro left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@Maffooch Maffooch merged commit 7fa55fc into DefectDojo:bugfix May 22, 2025
145 of 147 checks passed
@manuel-sommer manuel-sommer deleted the alibabacloudlinux3 branch May 22, 2025 05:45
xansec pushed a commit to xansec/django-DefectDojo that referenced this pull request Jun 18, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR ui

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants