Dapr september 2023 security audit report
run for a longer time and explore more of the reachable code. It also allows the fuzzers to keep testing the latest master branch as it evolves to test whether new bugs get introduced. Short-term, OSS-Fuzz .go and run it with go test -run=TestParsePublishMetadata2. func TestParsePublishMetadata2(t *testing.T) { m := &pubsub.PublishRequest{} m.Data = []byte{246, 255, 255, 255, 255, 10, 255, 32, 32, 32 pc=0xa3c850 testing.tRunner(0xc000288ea0, 0xc78960) /usr/local/go/src/testing/testing.go:1576 +0x10b fp=0xc000392fc0 sp=0xc000392f70 pc=0x53632b testing.(*T).Run.func1() /usr/local/go/src/testing/testing.go:16290 码力 | 47 页 | 1.05 MB | 1 年前3Dapr july 2020 security audit report
project was assigned to four members of the Cure53 team with best-suited expertise and skills. The testing team examined the scope in June 2020, namely in calendar weeks 24 and 25. A total budget allocated project channel, which was then used for questions and feedback, as well as broader verifications of testing and auditing ideas or directions. Cure53 shared status updates and discussed findings with Dapr as sections, the report will first shed light on the scope and key test parameters of this June 2020 testing exercise of Dapr. Next, all findings will be discussed in a chronological order alongside0 码力 | 19 页 | 267.84 KB | 1 年前3Dapr february 2021 security audit report
available on GitHub as OSS. In addition, a dedicated environment created by the Dapr team for the testing purposes was provided. White-box methodology, just as last time, has guided the work of Cure53. attention. The report will now present the scope and test setup as well as the material available for testing. Next, three tickets - one new finding and two collections of past vulnerabilities and weaknesses Vulnerabilities The following sections list both vulnerabilities and implementation issues spotted during the testing period. Note that findings are listed in chronological order rather than by their degree of severity0 码力 | 9 页 | 161.25 KB | 1 年前3Dapr june 2023 fuzzing audit report
https://github.com/golang/go/issues/60411#event-9334104392 ID: ADA-DAP-FUZZ-2 Description A fuzzer testing kit/crypto found that malicious raw bytes can be parsed into a key that will trigger a panic in the0 码力 | 19 页 | 690.59 KB | 1 年前3
共 4 条
- 1