Skip to content

Test design: Execution on console in AR scripts and escape special characters from JSON alert #2366

@damarisg

Description

@damarisg

Description

This issue aims to design and create tests to cover the Active response tools allow arbitrary code execution bug.

It was a critical bug that opened us CVE-2021-44079 and, then Wazuh could fix it here.

Scenario: Execute by console a command and check that it not is executed as code. (check cases).

To Do

  • Research the issue.
  • Define TCs, also identify if they require IT or System tests.
  • Create TCs.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions