Merge pull request #1924 from drwetter/fix_1915

Fix redundant message (BREACH) when client certificate required
This commit is contained in:
Dirk Wetter 2021-06-22 08:25:29 +02:00 committed by GitHub
commit 56dcbcdc15
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -16399,8 +16399,9 @@ run_breach() {
[[ $VULN_COUNT -le $VULN_THRESHLD ]] && outln && pr_headlineln " Testing for BREACH (HTTP compression) vulnerability " && outln
pr_bold " BREACH"; out " ($cve) "
if [[ "$CLIENT_AUTH" == required ]]; then
outln "cannot be tested (server side requires x509 authentication)"
fileout "$jsonID" "INFO" "was not tested, server side requires x509 authentication" "$cve" "$cwe"
prln_warning "client x509-based authentication prevents this from being tested"
fileout "$jsonID" "WARN" "client x509-based authentication prevents this from being tested" "$cve" "$cwe"
return 7
fi
[[ -z "$url" ]] && url="/"