Skip to content

Attaching empty files to Test with DefectDojo persistence provider #877

Description

@EndPositive

🐞 Bug report

Describe the bug

In some cases, scanners may output empty raw result files (e.g. Nuclei jsonl). When importing these into DefectDojo with the DefectDojo persistence provider, the hook fails with: Failed to attach findings to engagement.. DefectDojo reports a Bad Request. Uploading the same raw file in DefectDojo UI reports that the findings file may not be empty.

Steps To Reproduce

With DD, DD persistence, and Nuclei installed, run a Nuclei scan in SCB without any endpoints specified. This results in an empty raw result file for Nuclei.

Expected behavior

DefectDojo Test is made without any imported results.

System (please complete the following information):

  • secureCodeBox Version/Release: 3.5.0
  • DefectDojo Version: 2.4.1

Screenshots / Logs

[13/Dec/2021 09:18:08] WARNING [django.request:224] Bad Request: /api/v2/reimport-scan/
WARNING:django.request:Bad Request: /api/v2/reimport-scan/
[pid: 27|app: 0|req: 51/78] 172.17.0.1 () {40 vars in 727 bytes} [Mon Dec 13 09:18:08 2021] POST /api/v2/reimport-scan/ => generated 130 bytes in 12 msecs (HTTP/1.1 400) 7 headers in 203 bytes (1 switches on core 1)
2021-12-13 09:17:51 INFO  DefectDojoPersistenceProvider:24 - Starting DefectDojo persistence provider
2021-12-13 09:17:53 INFO  DefectDojoPersistenceProvider:35 - Downloading Scan Result
2021-12-13 09:17:55 INFO  DefectDojoPersistenceProvider:39 - Uploading Findings to DefectDojo at: http://defectdojo-django.default.svc.cluster.local
2021-12-13 09:17:57 INFO  VersionedEngagementsStrategy:87 - Running with DefectDojo User Id: 1
2021-12-13 09:17:57 INFO  VersionedEngagementsStrategy:200 - Looking for ID of ProductType 'Research and Development'
2021-12-13 09:17:57 INFO  VersionedEngagementsStrategy:207 - Using ProductType Id: 1
Exception in thread "main" io.securecodebox.persistence.defectdojo.exceptions.DefectDojoPersistenceException: Failed to attach findings to engagement.
	at io.securecodebox.persistence.defectdojo.service.ImportScanService.createFindings(ImportScanService.java:136)
	at io.securecodebox.persistence.defectdojo.service.ImportScanService.reimportScan(ImportScanService.java:151)
	at io.securecodebox.persistence.strategies.VersionedEngagementsStrategy.run(VersionedEngagementsStrategy.java:103)
	at io.securecodebox.persistence.DefectDojoPersistenceProvider.main(DefectDojoPersistenceProvider.java:42)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugBugsplannedIssues we will do in the next sprint.

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions