Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SP-6512] - Backport of PPP-5053 - Intercepting few Get request with Burp Suite allows un-authorised user to access data (9.3 Suite) #5574

Merged
merged 3 commits into from
Apr 10, 2024

Conversation

renato-s added 2 commits April 9, 2024 16:06
…Burp Suite allows un-authorised user to access data (9.3 Suite)
…Burp Suite allows un-authorised user to access data (9.3 Suite)

[PPP-5053] - Intercepting few Get request with Burp Suite allows un-authorised user to access data
@renato-s renato-s requested a review from a team as a code owner April 9, 2024 15:12
Copy link
Contributor

@andreramos89 andreramos89 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changed git repo and location, but seem consistent

@pentaho pentaho deleted a comment from buildguy Apr 10, 2024
@buildguy

This comment was marked as outdated.

…Burp Suite allows un-authorised user to access data (9.3 Suite) - Test Fix
Copy link

SonarQube Quality Gate

Quality Gate failed

Failed condition B Maintainability Rating on New Code (is worse than A)
Failed condition 48.0% 48.0% Coverage on New Code (is less than 80%)

See analysis details on SonarQube

Fix issues before they fail your Quality Gate with SonarLint SonarLint in your IDE.

@buildguy
Copy link
Collaborator

👍 Frogbot scanned this pull request and found that it did not add vulnerable dependencies.

Note:

Frogbot also supports Contextual Analysis, Secret Detection, IaC and SAST Vulnerabilities Scanning. This features are included as part of the JFrog Advanced Security package, which isn't enabled on your system.


@buildguy
Copy link
Collaborator

⚠️ Build finished in 35m 36s

Build command:

mvn clean verify -B -e -Daudit -Djs.no.sandbox -pl \
core,extensions,user-console

⛔ Failed Tests

⛈️ 1 test(s) failed:

org.pentaho.platform.util.versionchecker.PentahoVersionCheckReflectHelperTest.performVersionCheckTest (click to expand)

${result.errorDetails}

Tests run: 2175, Failures: 1, Skipped: 1    Test Results


ℹ️ This is an automatic message

@smmribeiro
Copy link
Contributor

Failing unit test is unrelated to these changes and is one that fails periodically.

@smmribeiro smmribeiro merged commit f9b2d9a into pentaho:9.3 Apr 10, 2024
0 of 2 checks passed
smmribeiro added a commit to smmribeiro/pentaho-platform that referenced this pull request Jun 28, 2024
…ting few Get request with Burp Suite allows un-authorised user to access data (9.3 Suite) (pentaho#5574)"

This partially reverts commit f9b2d9a.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants