mirror of
				https://github.com/drwetter/testssl.sh.git
				synced 2025-10-31 13:55:25 +01:00 
			
		
		
		
	Fix redundant message (BREACH) when client certificate required
same as #1916. Fixes #1915
This commit is contained in:
		| @@ -16399,8 +16399,9 @@ run_breach() { | ||||
|      [[ $VULN_COUNT -le $VULN_THRESHLD ]] && outln && pr_headlineln " Testing for BREACH (HTTP compression) vulnerability " && outln | ||||
|      pr_bold " BREACH"; out " ($cve)                    " | ||||
|      if [[ "$CLIENT_AUTH" == required ]]; then | ||||
|           outln "cannot be tested (server side requires x509 authentication)" | ||||
|           fileout "$jsonID" "INFO" "was not tested, server side requires x509 authentication" "$cve" "$cwe" | ||||
|           prln_warning "client x509-based authentication prevents this from being tested" | ||||
|           fileout "$jsonID" "WARN" "client x509-based authentication prevents this from being tested" "$cve" "$cwe" | ||||
|           return 7 | ||||
|      fi | ||||
| 
 | ||||
|      [[ -z "$url" ]] && url="/" | ||||
|   | ||||
		Reference in New Issue
	
	Block a user
	 Dirk
					Dirk