Thanks to visit codestin.com
Credit goes to github.com

Skip to content

2.45.2 pro changelog #12292

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Apr 24, 2025
Merged

Conversation

paulOsinski
Copy link
Contributor

Updating changelog for 2.45.2 DD Pro release.

Copy link

DryRun Security

This pull request contains potential security risks related to documentation link exposure and XML parser modifications that could lead to information disclosure and parsing vulnerabilities.

💭 Unconfirmed Findings (3)
Vulnerability Documentation Link Exposure
Description Security finding revealing internal documentation structure with potential information disclosure about tool integration paths
Vulnerability XML Parser Update Potential Risks
Description Modifications to XML parser could introduce parsing vulnerabilities, including potential XML external entity (XXE) injection risks
Vulnerability Potential Information Disclosure
Description Documentation links might expose sensitive path information that could be exploited

All finding details can be found in the DryRun Security Dashboard.

@Maffooch Maffooch added this to the 2.45.3 milestone Apr 22, 2025
Copy link
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@valentijnscholten valentijnscholten merged commit 84383b2 into DefectDojo:bugfix Apr 24, 2025
77 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants