January 5, 2021

ZAP seems to incorrectly report path traversal vulnerability in Angular app

I’m running OWASP ZAP as part of an automated CI/CD process. I am doing a spider and active scan. The report showed that there is a Path Traversal vulnerability.

This is an Angular 2 site and the javascript application is downloaded and runs in the local web browser so there wouldn’t be anything revealed on the server.

**Alert Detail**
**High (Medium) Path Traversal**
URL [http://localhost:8088/Mydir/login](http://localhost:8088/Mydir/login)
Method POST
Parameter usr
Attack login
Instances 1
CWE Id 22
WASC Id 33
Source ID 1


POST [http://localhost:8082/Mydir/login](http://localhost:8082/Mydir/login) HTTP/1.1 User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0 Accept: application/json, text/plain, */* Accept-Language: en-US Content-Type: application/json Content-Length: 28 Origin: [https://localhost](https://localhost/) Connection: keep-alive Referer: [https://localhost/Frontend/](https://localhost/Frontend/) Host: localhost:8088

HTTP/1.1 200 Access-Control-Allow-Origin: * Access-Control-Allow-Methods: GET, POST, PUT, DELETE, OPTIONS Access-Control-Max-Age: 3600 Access-Control-Allow-Headers: * Access-Control-Expose-Headers: xsrf-token Access-Control-Expose-Headers: xsrf-token X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: 0 X-Frame-Options: DENY Content-Type: application/json Date: Tue, 05 Jan 2021 08:41:50 GMT Keep-Alive: timeout=60 Connection: keep-alive —————————————————————-

Please let me know if you need any other information.


