With the help of Hacktron, Novu catches second-order vulnerabilities across a codebase 400+ contributors touch, without adding process or noise fatigue. Around half the security issues found by Hacktron in the first 30 days were fixed, and 83% were actionable. It also found a high-severity NoSQL injection that could have led to an attacker viewing, editing, or deleting a conversation that wasn't theirs. Hacktron’s Review caught this by tracing the call chain across three files: the ingest controller that accepts the raw event payload, the type cast without deep validation, and the sink service that passes the unvalidated ID into the NoSQL query.

https://t.co/QRbs8ARNTp
Hacktron's automated review caught a NoSQL injection in Novu by tracing an unvalidated event ID across three files, and fixed roughly half of flagged issues within 30 days with an 83% actionable rate.
Checking sign-in…
Loading comments…