From 6f16c9a41671650d5cd224ac6fc00bbc14a7c973 Mon Sep 17 00:00:00 2001 From: Thomas Baisley <132991176+NxtTAB@users.noreply.github.com> Date: Tue, 23 Jan 2024 14:49:12 +0100 Subject: [PATCH] Fix false positive: bei redirect to main page using Content-Location --- http/misconfiguration/ibm-friendly-path-exposure.yaml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/http/misconfiguration/ibm-friendly-path-exposure.yaml b/http/misconfiguration/ibm-friendly-path-exposure.yaml index 03e7d2e3b1..4595577b32 100644 --- a/http/misconfiguration/ibm-friendly-path-exposure.yaml +++ b/http/misconfiguration/ibm-friendly-path-exposure.yaml @@ -39,5 +39,11 @@ http: - type: status status: - 200 + + - type: regex + part: header + regex: + - "Content-Location: .+" + negative: true # digest: 4b0a00483046022100b8ffb455a810ccfda40f96bae3dcea77b4f56ea1d00eb89ba0114e9e3848f86c022100ae09577f1858fdc2203f5e21d548b4032dcf74c4489a6757df180c2361853698:922c64590222798bb761d5b6d8e72950