Skip to content
Open

Test #70

Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
34 commits
Select commit Hold shift + click to select a range
06e1425
fix: log4shell-goof/log4shell-server/pom.xml to reduce vulnerabilities
snyk-bot Jun 20, 2024
7228479
Create Dockerfile
dollav Sep 20, 2024
968472f
Update pom.xml
dollav Sep 23, 2024
7cbfc45
Update pom.xml
dollav Sep 23, 2024
bb36133
Update pom.xml
dollav Sep 23, 2024
af04ad5
test
dollav Sep 23, 2024
ac27272
release
dollav Sep 23, 2024
54b9c8d
test
dollav Sep 23, 2024
2a26328
Update pom.xml
dollav Sep 23, 2024
f817215
Update pom.xml
dollav Sep 23, 2024
2d4923c
Update pom.xml
dollav Sep 23, 2024
3911484
Update pom.xml
dollav Sep 23, 2024
1932bf3
Update pom.xml
dollav Sep 23, 2024
e162ed0
Update pom.xml
dollav Sep 23, 2024
d0f970e
Update pom.xml
dollav Sep 23, 2024
bb8901a
Update pom.xml
dollav Sep 23, 2024
bf9042c
Update pom.xml
dollav Sep 23, 2024
5061ab7
Update pom.xml
dollav Sep 23, 2024
7d0e84e
Update pom.xml
dollav Sep 23, 2024
17123a1
Update pom.xml
dollav Sep 23, 2024
9f915ec
Update pom.xml
dollav Sep 23, 2024
e563ece
Update pom.xml
dollav Sep 23, 2024
9eac259
Update pom.xml
dollav Sep 23, 2024
2255c17
Update pom.xml
dollav Sep 23, 2024
5570ad8
Update pom.xml
dollav Sep 23, 2024
f324861
Update pom.xml
dollav Sep 23, 2024
3925cb2
Update pom.xml
dollav Sep 24, 2024
8dc93ec
Update pom.xml
dollav Sep 24, 2024
1fba3dc
Update pom.xml
dollav Sep 24, 2024
42c4bec
Update pom.xml
dollav Oct 3, 2024
6f9f72c
Update pom.xml
dollav Oct 3, 2024
10b00d1
Update PriorityIconTag.java
dollav Feb 4, 2025
6d9a5e2
Update pom.xml
dollav Feb 4, 2025
8e4fa96
Update zip-slip.py
dollav Aug 5, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .vscode/settings.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{
"java.configuration.updateBuildConfiguration": "automatic"
}
6 changes: 6 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
From python:3.10.12-slim

RUN apt-get update
RUN apt-get install libkrb5support0 -y

RUN ["sleep", "1"]
36 changes: 32 additions & 4 deletions log4shell-goof/log4shell-server/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -4,18 +4,40 @@

<groupId>io.snyk</groupId>
<artifactId>log4shell-server</artifactId>
<version>0.0.1-SNAPSHOT</version>
<version>0.0.2-SNAPSHOT</version>
<packaging>jar</packaging>
<distributionManagement>
<snapshotRepository>
<id>privatedeps</id>
<name>snapshots</name>
<url>http://52.207.113.17:8081/nexus/content/repositories/snapshots</url>
</snapshotRepository>

<repository>
<id>privatedeps</id>
<url>http://52.207.113.17:8081/nexus/content/repositories/releases</url>
</repository>

</distributionManagement>
<name>Java Goof :: Log4Shell Goof :: Log4Shell Server</name>
<url>https://snyk.io</url>

<properties>
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<maven.compiler.source>8</maven.compiler.source>
<maven.compiler.target>8</maven.compiler.target>
</properties>

<repositories>
<repository>
<id>privatedeps</id>
<name>Aspose Java API</name>
<url>http://52.207.113.17:8081/nexus/content/repositories/releases</url>
</repository>
<repository>
<id>2</id>
<name>All apart from Aspose</name>
<url>http://52.207.113.17:8081/nexus/content/repositories/snapshots</url>
</repository>
</repositories>
<dependencies>
<dependency>
<groupId>org.apache.logging.log4j</groupId>
Expand All @@ -27,10 +49,15 @@
<artifactId>unboundid-ldapsdk</artifactId>
<version>3.1.1</version>
</dependency>
<dependency>
<groupId>io.snyk</groupId>
<artifactId>log4shell-server</artifactId>
<version>0.0.1-SNAPSHOT</version>
</dependency>
<dependency>
<groupId>io.undertow</groupId>
<artifactId>undertow-core</artifactId>
<version>2.2.13.Final</version>
<version>2.3.14.Final</version>
</dependency>
<dependency>
<groupId>commons-collections</groupId>
Expand Down Expand Up @@ -81,4 +108,5 @@
</plugins>

</build>

</project>
15 changes: 15 additions & 0 deletions log4shell-goof/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -19,4 +19,19 @@
<module>log4shell-server</module>
<module>log4shell-client</module>
</modules>

<distributionManagement>
<snapshotRepository>
<id>my-snapshots</id>
<name>My internal repository</name>
<url>http://52.207.113.17/:8081/nexus/content/repositories/snapshots</url>
</snapshotRepository>

<repository>
<id>my-releases</id>
<name>My internal repository</name>
<url>http://52.207.113.17/:8081/nexus/content/repositories/releases</url>
</repository>

</distributionManagement>
</project>
2 changes: 2 additions & 0 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@
<module>todolist-goof</module>
<module>log4shell-goof</module>
</modules>


<packaging>pom</packaging>


Expand Down
3 changes: 3 additions & 0 deletions todolist-goof/exploits/zip-slip.py
Original file line number Diff line number Diff line change
Expand Up @@ -11,3 +11,6 @@
files = {'upload': ('zip-slip.zip', open(malicious_zip, 'rb'), 'application/zip')}

requests.post(url, files=files)
requests.post(url, files=files)
requests.post(url, files=files)
requests.post(url, files=files)
30 changes: 23 additions & 7 deletions todolist-goof/todolist-core/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,19 @@

<artifactId>todolist-core</artifactId>
<packaging>jar</packaging>

<distributionManagement>
<snapshotRepository>
<id>privatedeps</id>
<name>snapshots</name>
<url>http://52.207.113.17:8081/nexus/content/repositories/snapshots</url>
</snapshotRepository>

<repository>
<id>privatedeps</id>
<url>http://52.207.113.17:8081/nexus/content/repositories/releases</url>
</repository>

</distributionManagement>
<name>Java Goof :: Todolist Goof :: Todolist Core</name>

<dependencies>
Expand All @@ -26,12 +38,16 @@
<artifactId>spring-orm</artifactId>
<version>${spring.version}</version>
</dependency>

<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-aspects</artifactId>
<version>${spring.version}</version>
</dependency>
<dependency>
<groupId>io.snyk</groupId>
<artifactId>log4shell-server</artifactId>
<version>0.2.3</version>
</dependency>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-aspects</artifactId>
<version>${spring.version}</version>
</dependency>

<!-- AOP dependency -->
<dependency>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@
*/

package io.github.benas.todolist.web.common.tags;
package io.github.benas.todolist.web.common.tags2;

import io.github.benas.todolist.web.common.util.TodoListUtils;
import io.github.todolist.core.domain.Priority;
Expand Down