Python: Implement check for flask debug mode.#528
Merged
Conversation
1ced7d8 to
b393d9a
Compare
Contributor
Author
|
Updated the test results and added a change note. |
markshannon
suggested changes
Nov 27, 2018
| * @description Running a Flask app in debug mode may allow an attacker to run arbitrary code through the Werkzeug debugger. | ||
| * @kind problem | ||
| * @problem.severity error | ||
| * @precision medium |
Contributor
There was a problem hiding this comment.
This seems low. I think this merits "high".
markshannon
approved these changes
Nov 27, 2018
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Does not include a change in the change notes. This will be added in a separate PR.
Also changes the
.expectedfile forCWE-079/ReflectedXss.qlslightly, due to a small change in the flask library stubs.