
Product Announcements — shinksmon (Veracode, Inc.) asked a question.
This month, we’ve added a new lab, OWASP 9 Security Logging and Monitoring Failures - Hold the Line, which is JavaScript (node) lab that covers CRLF Injection. CRLF Injections are some of the most commonly found vulnerabilities. In fact, CWE-117, a logging specific example of a CRLF Injection, occurs frequently across Veracode scans. This lab explains how attackers use CRLF injection to flood log files with false events, and how to remediate a CRLF vulnerability. The Security Labs Course Catalog is updated to reflect these changes.
.png)
👍