Merge pull request #726 from oerdnj/2.9dev-no-downgrade-breach

Revert "Downgrade BREACH attack to MEDIUM severity"
This commit is contained in:
Dirk Wetter 2017-04-25 23:10:11 +02:00 committed by GitHub
commit ef10fc3119

View File

@ -9548,7 +9548,7 @@ run_breach() {
pr_svrty_high "potentially NOT ok, uses $result HTTP compression."
outln "$disclaimer"
outln "$spaces$when_makesense"
fileout "breach" "MEDIUM" "BREACH: potentially VULNERABLE, uses $result HTTP compression. $disclaimer ($when_makesense)" "$cve" "$cwe" "$hint"
fileout "breach" "HIGH" "BREACH: potentially VULNERABLE, uses $result HTTP compression. $disclaimer ($when_makesense)" "$cve" "$cwe" "$hint"
ret=1
fi
# Any URL can be vulnerable. I am testing now only the given URL!