Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding file producer metadata leakage #788

Open
Hipapheralkus opened this issue Aug 26, 2021 · 2 comments
Open

Adding file producer metadata leakage #788

Hipapheralkus opened this issue Aug 26, 2021 · 2 comments
Labels
new New content to write

Comments

@Hipapheralkus
Copy link

File producer metadata leakage
If the web application generates files (e.g. pdf), using exiftools (or other techniques), the Producer can be found which created it. If the producer is known, e.g. Producer: iText 2.1.7 or Producer: mPDF 7.1.7 the attacker can discover whether any CVEs exist for such a tool leading to successful exploitation.

Although I was able to find https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/01-Information_Gathering/, but it doesn't reference this specific need in my opinion. Therefore, I'd like to extend the Information Gathering with a new content.

Would you like to be assigned to this issue?
no

@Hipapheralkus Hipapheralkus added help wanted new New content to write labels Aug 26, 2021
@kingthorin
Copy link
Collaborator

@Hipapheralkus you said you'd like extend/add content but then didn't want the issue assigned. Do you plan to tackle the changes?

@github-actions
Copy link

Please comment if you are still working on this issue, as it has been inactive for 90 days. To give everyone a chance to contribute, we are releasing it to new contributors.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
new New content to write
Projects
None yet
Development

No branches or pull requests

2 participants