Skip to content
Failed

Changes

Summary

  1. [ApiRsMonitoraggio] (commit: 36a8560) (details)
  2. [GovWayCore] (commit: a785355) (details)
  3. [GovWayConsole, GovWayMonitor] (commit: 2308c72) (details)
  4. [GovWayConsole, GovWayMonitor] (commit: 8ce1b6e) (details)
Commit 36a8560adcfa9acc6eb7f94c512f159844183da9 by Andrea Poli
[ApiRsMonitoraggio]
Risolto problema in cui venivano serializzate le informazioni sul contenuto, senza la presenza del content-type obbligatorio.
(commit: 36a8560)
The file was modifiedcore/src/org/openspcoop2/pdd/logger/traccia/Converter.java (diff)
Commit a7853552717cfead4989a350983d672c7d894d75 by Andrea Poli
[GovWayCore]
Corretti errori testsuite
(commit: a785355)
The file was modifiedtools/utils/src/org/openspcoop2/utils/transport/http/HttpUtilities.java (diff)
The file was modifiedtools/utils/src/org/openspcoop2/utils/transport/http/HttpCoreConnection.java (diff)
Commit 2308c728e152e54004b4c3d3e50c2e408001f000 by Andrea Poli
[GovWayConsole, GovWayMonitor]
Sono state risolte le seguenti vulnerabilità relative alle console di gestione e monitoraggio:
- CWE-307 (Brute Force)
- CWE-384 (Session Fixation)
(commit: 2308c72)
The file was modifiedtools/web_interfaces/control_station/deploy/properties/console.properties (diff)
The file was modifiedtools/web_interfaces/control_station/src/org/openspcoop2/web/ctrlstat/config/ConsoleProperties.java (diff)
The file was modifiedChangeLog (diff)
The file was addedtools/web_interfaces/lib/mvc/src/org/openspcoop2/web/lib/mvc/login/FailedAttempts.java
The file was modifiedtools/web_interfaces/control_station/src/org/openspcoop2/web/ctrlstat/servlet/login/Login.java (diff)
The file was modifiedtools/web_interfaces/control_station/src/org/openspcoop2/web/ctrlstat/core/InitListener.java (diff)
The file was modifiedtools/web_interfaces/lib/mvc/src/org/openspcoop2/web/lib/mvc/ServletUtils.java (diff)
The file was addedtools/web_interfaces/lib/mvc/src/org/openspcoop2/web/lib/mvc/login/package.html
The file was modifiedtools/web_interfaces/monitor/src/src_core/org/openspcoop2/web/monitor/core/listener/ConsoleStartupListener.java (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/properties/monitor.properties (diff)
The file was addedtools/web_interfaces/monitor/testsuite/verifica_accesso_console_monitoraggio.sh
The file was modifiedtools/web_interfaces/control_station/src/org/openspcoop2/web/ctrlstat/servlet/login/AuthorizationFilter.java (diff)
The file was modifiedtools/web_interfaces/monitor/src/src_core/org/openspcoop2/web/monitor/core/dao/ILoginDAO.java (diff)
The file was addedresources/doc/src/manuali/vulnerability-management/falsePositive/33x/CVE-2025-10492.rst
The file was addedresources/doc/src/manuali/vulnerability-management/securityAdvisory/2025/CWE-307.rst
The file was modifiedtools/web_interfaces/monitor/src/src_core/org/openspcoop2/web/monitor/core/bean/AbstractLoginBean.java (diff)
The file was modifiedtools/web_interfaces/control_station/src/org/openspcoop2/web/ctrlstat/core/ControlStationCore.java (diff)
The file was addedtools/web_interfaces/lib/mvc/src/org/openspcoop2/web/lib/mvc/login/LoginException.java
The file was modifiedtools/web_interfaces/control_station/src/org/openspcoop2/web/ctrlstat/servlet/login/Logout.java (diff)
The file was modifiedtools/web_interfaces/monitor/src/src_core/org/openspcoop2/web/monitor/core/bean/LoginBean.java (diff)
The file was modifiedtools/web_interfaces/monitor/src/src_core/org/openspcoop2/web/monitor/core/dao/DBLoginDAO.java (diff)
The file was addedresources/doc/src/manuali/vulnerability-management/securityAdvisory/2025/CWE-384.rst
The file was addedtools/web_interfaces/lib/mvc/src/org/openspcoop2/web/lib/mvc/login/LoginAttempt.java
The file was modifiedtools/web_interfaces/monitor/src/src_core/org/openspcoop2/web/monitor/core/core/PddMonitorProperties.java (diff)
The file was addedtools/web_interfaces/control_station/testsuite/verifica_accesso_console_gestione.sh
The file was modifiedtools/web_interfaces/monitor/src/src_core/org/openspcoop2/web/monitor/core/filters/PrincipalFilter.java (diff)
The file was modifiedresources/doc/src/manuali/vulnerability-management/securityAdvisory/2025/index.rst (diff)
The file was modifiedtools/web_interfaces/control_station/src/org/openspcoop2/web/ctrlstat/servlet/login/LoginHelper.java (diff)
Commit 8ce1b6e186a26b87bbd8709a101a25dd2f38eec2 by Andrea Poli
[GovWayConsole, GovWayMonitor]
È stata risolte la seguente vulnerabilità relativa alle console di gestione e monitoraggio:
- CWE-200 (Information Exposure): esposizione delle Versioni delle Librerie Frontend

Squashed commit of the following:

commit 54b5b3d5508612df779993d225025222d0c37af4
Author: Giuliano Pintori <pintori@link.it>
Date:   Mon Oct 6 15:05:09 2025 +0200

    [GovWayConsole]
    Risoluzione vulnerabilita Information Exposure (CWE-200)

    [GovWayMonitor]
    Risoluzione vulnerabilita Information Exposure (CWE-200)
(commit: 8ce1b6e)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/stat/pages/form/distribAzioneGrafico.xhtml (diff)
The file was modifiedlib/openspcoop2.userlibraries (diff)
The file was modifiedmvn/dependencies/console/pom.xml (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/transazioni/pages/form/dettaglioDumpMultipart.xhtml (diff)
The file was addedtools/web_interfaces/lib/js/bootstrap-tagsinput.min.js
The file was modifiedtools/web_interfaces/monitor/build.xml (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/commons/includes/summary.xhtml (diff)
The file was modifiedtools/web_interfaces/monitor/ant/openspcoop2-govwayMonitor-resource.xml (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/stat/pages/form/distribServizioGrafico.xhtml (diff)
The file was removedtools/web_interfaces/lib/js/jquery.searchabledropdown-1.0.8.min.js
The file was modifiedtools/web_interfaces/monitor/deploy/pages/transazioni/pages/form/dettaglioDumpTransazioneApplicativoServer.xhtml (diff)
The file was addedtools/web_interfaces/lib/js/jquery.searchabledropdown.min.js
The file was modifiedtools/web_interfaces/monitor/deploy/pages/transazioni/pages/form/dettaglioDump.xhtml (diff)
The file was modifiedtools/web_interfaces/monitor/ant/openspcoop2-govwayMonitor-war.xml (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/stat/pages/form/distribSAGrafico.xhtml (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/transazioni/pages/form/fault.xhtml (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/transazioni/pages/form/faultTransazioneApplicativoServer.xhtml (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/transazioni/pages/form/tokenInfo.xhtml (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/stat/pages/form/andamentoTemporaleGrafico.xhtml (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/stat/pages/form/statistichePdndTracingDettaglio.xhtml (diff)
The file was modifiedChangeLog (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/stat/pages/form/distribSoggettoGrafico.xhtml (diff)
The file was addedtools/web_interfaces/monitor/deploy/web-content/scripts/c3.min.js
The file was modifiedtools/web_interfaces/monitor/src/WEB-INF/web/web.xml.filters (diff)
The file was modifiedtools/web_interfaces/control_station/ant/openspcoop2-govwayConsole-war.xml (diff)
The file was modifiedtools/web_interfaces/lib/jsplib/addElement.jsp (diff)
The file was addedtools/web_interfaces/monitor/deploy/web-content/scripts/shBrushXml.min.js
The file was addedtools/web_interfaces/lib/js/typeahead.bundle.min.js
The file was modifiedtools/web_interfaces/monitor/deploy/pages/stat/pages/form/distribErroriGrafico.xhtml (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/stat/pages/form/statsPersonalizzateGrafico.xhtml (diff)
The file was addedtools/web_interfaces/lib/js/array-utils.min.js
The file was addedtools/web_interfaces/monitor/deploy/web-content/scripts/shCore.min.js
The file was addedtools/web_interfaces/monitor/deploy/web-content/scripts/XRegExp.min.js
The file was modifiedtools/web_interfaces/monitor/deploy/pages/transazioni/pages/form/visualizzaTraccia.xhtml (diff)
The file was modifiedtools/web_interfaces/control_station/src/WEB-INF/web/web.xml.filters (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/transazioni/pages/form/dettaglioDumpTransazioneApplicativoServerMultipart.xhtml (diff)
The file was modifiedtools/web_interfaces/lib/jsplib/listElement.jsp (diff)
The file was modifiedtools/web_interfaces/monitor/deploy/pages/transazioni/pages/form/esitiLive.xhtml (diff)
The file was addedtools/web_interfaces/lib/js/autocomplete.min.js
The file was modifiedtools/web_interfaces/lib/jsplib/templateHeader.jsp (diff)
The file was modifiedtools/web_interfaces/control_station/build.xml (diff)
The file was modifiedresources/doc/src/manuali/vulnerability-management/securityAdvisory/2025/index.rst (diff)
The file was addedtools/web_interfaces/monitor/deploy/web-content/scripts/shBrushJson.min.js