Skip to content

Changes

Started 3 days 0 hr ago
Took 20 hr

Summary

  1. [GovWayCore] (commit: 7e7b135) (details)
  2. [Documentazione] (commit: 8ad22a3) (details)
Commit 7e7b135798af58187e275909447268fb152614df by Andrea Poli
[GovWayCore]
Corretta la validazione del claim 'htu' del token DPoP (RFC 9449) in presenza di regole di proxy pass che riscrivono il contesto dell'URL di invocazione rimuovendo il soggetto:
l'URL ricostruita per il confronto ora utilizza correttamente il contesto riscritto dalla regola e il resource path della risorsa invocata.
(commit: 7e7b135)
The file was modifiedcore/src/org/openspcoop2/pdd/core/token/GestoreTokenValidazioneUtilities.java (diff)
The file was modifiedChangeLog (diff)
Commit 8ad22a39da76598f86305086c2b5bf12e4fa6783 by Andrea Poli
[Documentazione]
Aggiunto falso positivo CVE-2025-15599
(commit: 8ad22a3)
The file was addedresources/doc/src/manuali/vulnerability-management/falsePositive/34x/CVE-2025-15599.rst
The file was modifiedmvn/dependencies/pom.xml (diff)
The file was addedmvn/dependencies/owasp/falsePositives/swagger-ui.xml
The file was modifiedresources/doc/src/manuali/vulnerability-management/falsePositive/34x/index.rst (diff)