Alfred Berg
Security Researcher
New tests released based on submissions by our Detectify Crowdsource hackers:
- CVE-2023-38203: Adobe ColdFusion Deserialization of Untrusted Data
- ConnectWise Setup Exposure
New tests released by Detectify staff:
- Copia Installer Exposure
- JWT Arbitrary Key Url
- Mercurial Configuration File ("hgrc") Exposure
- SAP Web Administration Interface Exposure
Improved tests to reduce false negatives:
- Environment Variable Disclosure
- Shell-Script Exposure
Improved tests to reduce false positives:
- Statamic Configuration Exposure
- Docker-Compose Configuration Exposure
- WP Engine: Cache Poisoned Denial Of Service
Test now running in both Application scanning and Surface Monitoring, previously only in Application scanning:
- Atlassian Confluence Macro 'linking' SSRF
- Apache Syncope Default Credentials
- Bitrix Path Disclosure
- Core Dump Disclosure
- Cacti Unauthenticated Access
- Cockpit Blind SSRF
- Citrix XenMobile XXE