Skip to content

Conversation

paulOsinski
Copy link
Contributor

@paulOsinski paulOsinski commented Apr 24, 2025

In 2.45.2 , a new feature was added to DefectDojo Pro for estimating a Finding's Priority and Risk based on business context. This PR adds documentation for the feature and updates the changelog to incorporate that.

Copy link

dryrunsecurity bot commented Apr 24, 2025

DryRun Security

This pull request contains documentation that reveals internal prioritization methodologies and sensitive product metadata, which could potentially provide insights to attackers about the system's assessment strategies and product details.

💭 Unconfirmed Findings (3)
Vulnerability Information Disclosure Risk
Description Documentation reveals internal prioritization methodology and provides insights that could potentially assist attackers in understanding system assessment strategies.
Vulnerability Sensitive Information Exposure
Description Contains references to sensitive product metadata, including estimated revenue and user record counts, which could be problematic if inappropriately disclosed.
Vulnerability Potential Access Control Implications
Description Highlights tiered feature access between standard and Pro versions, indicating differentiated prioritization capabilities across product tiers.

All finding details can be found in the DryRun Security Dashboard.

Copy link
Contributor

This pull request has conflicts, please resolve those before we can evaluate the pull request.

Copy link
Contributor

Conflicts have been resolved. A maintainer will review the pull request shortly.

Copy link
Contributor

@cneill cneill left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just a couple nits, otherwise good to approve after Matt's comment is resolved

@paulOsinski paulOsinski requested a review from mtesauro April 25, 2025 15:48
Copy link
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@mtesauro mtesauro merged commit 5bf2349 into DefectDojo:bugfix Apr 25, 2025
78 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants