Product Announcements — shinksmon (Veracode, Inc.) asked a question.

🆕 Now Available in Security Labs: OWASP 9 - CRLF Injection

This month, we’ve added a new lab, OWASP 9 Security Logging and Monitoring Failures - Hold the Line, which is JavaScript (node) lab that covers CRLF Injection. CRLF Injections are some of the most commonly found vulnerabilities. In fact, CWE-117, a logging specific example of a CRLF Injection, occurs frequently across Veracode scans. This lab explains how attackers use CRLF injection to flood log files with false events, and how to remediate a CRLF vulnerability. The Security Labs Course Catalog is updated to reflect these changes.  


lucas.ferreira and DFerguson like this.

Topics (7)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.