Skip to content

params: Remove/unlink params content (being moved to add-on) - #631

Draft
kingthorin wants to merge 1 commit into
zaproxy:mainfrom
kingthorin:remove-params
Draft

params: Remove/unlink params content (being moved to add-on)#631
kingthorin wants to merge 1 commit into
zaproxy:mainfrom
kingthorin:remove-params

Conversation

@kingthorin

Copy link
Copy Markdown
Member

@psiinon

psiinon commented Jan 30, 2026

Copy link
Copy Markdown
Member

Logo
Checkmarx One – Scan Summary & Detailsc08d8785-f95d-4d6e-ada6-d2971892b9dd


New Issues (13) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 HIGH CVE-2025-48734 Maven-commons-beanutils:commons-beanutils-1.9.4
detailsRecommended version: 1.11.0
Description: An Improper Access Control vulnerability exists in Apache Commons. A special "BeanIntrospector" class was added in version 1.9.2. This can be used ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 HIGH Cx78f40514-81ff Maven-commons-collections:commons-collections-3.2.2
detailsDescription: The framework Apache Commons Collections before 4.3 is vulnerable to Stack Overflow. The function `add()` in the file `SetUniqueList.java` throws a...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
3 MEDIUM CVE-2012-5783 Maven-commons-httpclient:commons-httpclient-3.1
detailsDescription: Apache Commons HttpClient prior to 4.0-alpha1, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not ver...
Attack Vector: NETWORK
Attack Complexity: MEDIUM
Vulnerable Package
4 MEDIUM CVE-2012-6153 Maven-commons-httpclient:commons-httpclient-3.1
detailsDescription: http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain na...
Attack Vector: NETWORK
Attack Complexity: MEDIUM
Vulnerable Package
5 MEDIUM CVE-2020-13956 Maven-commons-httpclient:commons-httpclient-3.1
detailsDescription: Apache HttpClient can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong ta...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
6 MEDIUM CVE-2022-27820 Maven-org.zaproxy:zap-2.16.0
detailsDescription: OWASP Zed Attack Proxy (ZAP) does not verify the TLS certificate chain of an HTTPS server.
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
7 MEDIUM CVE-2025-46392 Maven-commons-configuration:commons-configuration-1.10
detailsDescription: Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration versions 1.x. There are a number of issues in Apache Commons Confi...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
8 MEDIUM CVE-2025-48924 Maven-commons-lang:commons-lang-2.6
detailsRecommended version: 2.7-atlassian-1
Description: Uncontrolled Recursion vulnerability in Apache Commons Lang. The methods `ClassUtils.getClass(...)` can `throwStackOverflowError` on very long inpu...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
9 MEDIUM CVE-2025-48924 Maven-org.apache.commons:commons-lang3-3.17.0
detailsRecommended version: 3.18.0
Description: Uncontrolled Recursion vulnerability in Apache Commons Lang. The methods `ClassUtils.getClass(...)` can `throwStackOverflowError` on very long inpu...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
10 MEDIUM CVE-2025-68161 Maven-org.apache.logging.log4j:log4j-core-2.24.2
detailsRecommended version: 2.25.4
Description: The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
11 MEDIUM CVE-2026-34478 Maven-org.apache.logging.log4j:log4j-core-2.24.2
detailsRecommended version: 2.25.4
Description: Apache Log4j Core's Rfc5424Layout https://logging\.apache\.org/log4j/2\.x/manual/layouts\.html\#RFC5424Layout , in versions 2.21.0 through 2.25.3, and ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
12 MEDIUM CVE-2026-34479 Maven-org.apache.logging.log4j:log4j-1.2-api-2.24.2
detailsRecommended version: 2.25.4
Description: The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standard, producing malformed XML...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
13 MEDIUM CVE-2026-34480 Maven-org.apache.logging.log4j:log4j-core-2.24.2
detailsRecommended version: 2.25.4
Description: Apache Log4j Core's XmlLayout https://logging\.apache\.org/log4j/2\.x/manual/layouts\.html\#XmlLayout , versions through 2.25.3, and 3.x through 3.0.0-...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

@thc202

thc202 commented Jan 30, 2026

Copy link
Copy Markdown
Member

This can only be merged when the add-on is in actual use/ready.

Comment thread addOns/help/src/main/javahelp/contents/start/features/httpsessions.html Outdated
@kingthorin

Copy link
Copy Markdown
Member Author

Okay,want me to convert to draft for now?

@thc202

thc202 commented Jan 30, 2026

Copy link
Copy Markdown
Member

I'm fine leaving as is, as long as we don't merge it before time.

@kingthorin

kingthorin commented Feb 1, 2026

Copy link
Copy Markdown
Member Author

Who knows how long this might sit, we don’t have a release plan yet so just so there’s no mistakes in like two months or something draft will be safer 😉

@thc202

thc202 commented May 26, 2026

Copy link
Copy Markdown
Member

The target ui.tabs.params needs to be removed from the map file.

Signed-off-by: kingthorin <kingthorin@users.noreply.github.com>
@kingthorin

Copy link
Copy Markdown
Member Author

Done

@thc202

thc202 commented May 27, 2026

Copy link
Copy Markdown
Member

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants