Skip to content

Add CVE-2025-0655 Detector #613

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 3 commits into
base: master
Choose a base branch
from
Open

Conversation

frkngksl
Copy link
Contributor

Hi @tooryx , @maoning ,

This is the plugin PR that resolves #610

Testbed PR for Vulnerable and Fixed Environment: google/security-testbeds#131

@alessandro-Doyensec
Copy link

Hey @frkngksl

Thanks for the contribution, I've taken a brief look at the plugin but I'm waiting on google/security-testbeds#131 (comment) to do a full evaluation.

In the meantime it seems that a newline is missing from community/detectors/dtale_cve_2025_0655/src/main/java/com/google/tsunami/plugins/detectors/cves/cve20250655/Cve20250655VulnDetector.java

Thanks again

@frkngksl
Copy link
Contributor Author

Hi @alessandro-Doyensec ,

I've already used Google Formatter, but I might miss something of course. Could you please tell me which line is the problem?

@alessandro-Doyensec
Copy link

Hi @alessandro-Doyensec ,

I've already used Google Formatter, but I might miss something of course. Could you please tell me which line is the problem?

Of course, the last newline (at the end of the file) is missing

@frkngksl
Copy link
Contributor Author

Hi @alessandro-Doyensec ,

I've added a newline and waiting for your full review.

@alessandro-Doyensec
Copy link

Hey @frkngksl everything is looking good, I just left a comment but nothing big.

I was able to verify that the plugin works correctly thanks to the testbed patch you added

@frkngksl
Copy link
Contributor Author

Hi @alessandro-Doyensec ,

Thank you for your review, if it's okay for you, we can discuss your comment under the review comments.

@alessandro-Doyensec
Copy link

LGTM - Approved
@maoning, can be merged together with the google/security-testbeds#131.

Reviewer: Alessandro, Doyensec
Drawbacks: None.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

AI PRP: RCE via Global State Override in dtale CVE-2025-0655
3 participants