Details
-
Improvement
-
Status: Open
-
Major
-
Resolution: Unresolved
-
None
-
None
-
None
Description
giorgio in FINERACT-853 suggested to run https://www.zaproxy.org against Fineract.
That sounds like a Great Idea - and may yield some interesting results and holes worth plugging.
I this is easier to do against a public server instead of locally, then I hereby offer https://www.fineract.dev for this purpose. As its FAQ says, quote: "Try to crash our demo - and if you manage, then work with us in the open source project to make the Fineract code more scaleable and reliable!"
Attachments
Attachments
Issue Links
- blocks
-
FINERACT-865 Strengthen/Harden Fineract 1.x to LTS Version by Upgrading Java & Improving Code Coverage of Tests
- Closed
- is blocked by
-
FINERACT-879 Refine overly permissive Cross-Origin Resource Sharing (CORS) policy
- Open
- is part of
-
FINERACT-1306 Reporting meta-data entry not found - All reports modules
- Resolved
-
FINERACT-1338 SQL Injection - While "runreports" api is trying to load report parameters
- Closed
- is related to
-
FINERACT-967 lgtm.com Security Vulnerability Assessment Scanning
- Closed
- relates to
-
FINERACT-854 Use prepared statements instead of string concatenated SQL everywhere
- In Progress
-
FINERACT-988 Snyk.io Security Vulnerability Assessment Scanning
- Closed