Skip to content

Instantly share code, notes, and snippets.

@adulau
Created October 19, 2019 08:05
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 1 You must be signed in to fork a gist
  • Save adulau/dce5a6ca5c65017869bb01dfee576303 to your computer and use it in GitHub Desktop.
Save adulau/dce5a6ca5c65017869bb01dfee576303 to your computer and use it in GitHub Desktop.
Finding security vulnerabilities from git commit messages

regexp

strong_vuln
_patterns
(?i)(denial.o f .service |\bXX E\b|remote.code.execution|\bopen.redirect|OSVDB|\bvuln|\bCVE\b
|\bXSS\b|\bReDoS\b|\bNVD\b|malicious|x − f rame − options|attack|cross.site |exploit|directory.
traversal |\bRCE\b|\bdos\b|\bXSRF \b|clickjack|session.fixation|hijack|advisory|insecure |security
|\bcross − oriдin\b|unauthori[z|s]ed |in finite.loop)
medium_vuln
_patterns
(?i)(authenticat(e |ion)|brute f orce |bypass|constant.time |crack|credential|\bDoS\b|expos(e |inд)|hack
|harden|injection|lockout|over flow|password |\bPoC\b|proo f.o f .concept|poison|privelaдe |\b(in)?secur
(e |ity)|(de )?serializ|spoo f |timinд|traversal)

ref

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment