Skip to content

Fix: Credential masking and add path traversal validation - #1106

Merged
rsenden merged 7 commits into
fortify:dev/v3.xfrom
jmadhur87:mjain6/FAAVulnFix4
Sep 23, 2026
Merged

rsenden merged 7 commits into
fortify:dev/v3.xfrom
jmadhur87:mjain6/FAAVulnFix4

Conversation

@jmadhur87

Copy link
Copy Markdown
Contributor

1. Credential Masking Fixes

  • Fixed broken log masking for Aviator admin private keys and user tokens
  • Moved @MaskValue annotations from field level to class level where log masking framework expects them

2. Reduced Token Logging

  • Removed full token values from INFO-level logs in token revocation/deletion commands
  • Logs now only identify the email address without exposing the token itself

3. Path Traversal Validation

  • Added version string validation in ToolInstallationDescriptor
  • Validates that tool version strings contain only safe characters [A-Za-z0-9._+-]
  • Blocks path traversal attempts (e.g., ../../sensitive-file) in externally-sourced tool-definitions

@rsenden
rsenden merged commit be4d2aa into fortify:dev/v3.x Sep 23, 2026
14 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants