Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update main.yml #48

Open
wants to merge 2 commits into
base: main
Choose a base branch
from
Open

Update main.yml #48

wants to merge 2 commits into from

Conversation

margaritalm
Copy link
Owner

No description provided.

@margaritalm
Copy link
Owner Author

margaritalm commented Aug 13, 2024

Logo
Checkmarx One – Scan Summary & Details8b15add1-7dea-4718-8ecb-692452c07250

Policy Management Violations

Policy Name Rule(s) Break Build
NewPolicyBug NumverOfHugh false

New Issues

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2015-6420 Maven-commons-collections:commons-collections-3.2.1 Vulnerable Package
HIGH CVE-2016-2170 Maven-commons-collections:commons-collections-3.2.1 Vulnerable Package
HIGH CVE-2016-5007 Maven-org.springframework:spring-core-4.3.0.RELEASE Vulnerable Package
HIGH CVE-2017-5645 Maven-org.apache.logging.log4j:log4j-core-2.3 Vulnerable Package
HIGH CVE-2017-8028 Maven-org.springframework.ldap:spring-ldap-core-2.1.0.RELEASE Vulnerable Package
HIGH CVE-2018-1272 Maven-org.springframework:spring-core-4.3.0.RELEASE Vulnerable Package
HIGH CVE-2019-17571 Maven-org.apache.logging.log4j:log4j-core-2.3 Vulnerable Package
HIGH CVE-2021-44228 Maven-org.apache.logging.log4j:log4j-core-2.3 Vulnerable Package
HIGH CVE-2021-45046 Maven-org.apache.logging.log4j:log4j-core-2.3 Vulnerable Package
HIGH CVE-2022-22965 Maven-org.springframework:spring-beans-4.2.5.RELEASE Vulnerable Package
HIGH Cx78f40514-81ff Maven-commons-collections:commons-collections-3.2.1 Vulnerable Package
HIGH Missing User Instruction /Dockerfile: 33 A user should be specified in the dockerfile, otherwise the image will run as root
HIGH SQL_Injection /BookDetail_jsp.java: 173 Attack Vector
HIGH SQL_Injection /BookDetail_jsp.java: 173 Attack Vector
HIGH SQL_Injection /test/Checkmarkscan.java: 19 Attack Vector
MEDIUM CSRF /BookDetail_jsp.java: 173 Attack Vector
MEDIUM CSRF /BookDetail_jsp.java: 173 Attack Vector
MEDIUM CVE-2018-1199 Maven-org.springframework:spring-core-4.3.0.RELEASE Vulnerable Package
MEDIUM CVE-2018-1257 Maven-org.springframework:spring-test-4.3.1.RELEASE Vulnerable Package
MEDIUM CVE-2020-13956 Maven-org.apache.httpcomponents:httpclient-4.5.8 Vulnerable Package
MEDIUM CVE-2020-15250 Maven-junit:junit-4.11 Vulnerable Package
MEDIUM CVE-2020-15250 Maven-junit:junit-4.12 Vulnerable Package
MEDIUM CVE-2021-22060 Maven-org.springframework:spring-core-4.3.0.RELEASE Vulnerable Package
MEDIUM CVE-2021-22096 Maven-org.springframework:spring-core-4.3.0.RELEASE Vulnerable Package
MEDIUM CVE-2021-29425 Maven-commons-io:commons-io-2.4 Vulnerable Package
MEDIUM CVE-2021-29425 Maven-commons-io:commons-io-2.5 Vulnerable Package
MEDIUM CVE-2021-44832 Maven-org.apache.logging.log4j:log4j-core-2.3 Vulnerable Package
MEDIUM CVE-2021-45105 Maven-org.apache.logging.log4j:log4j-core-2.3 Vulnerable Package
MEDIUM CVE-2022-22950 Maven-org.springframework:spring-core-4.3.0.RELEASE Vulnerable Package
MEDIUM CVE-2022-22950 Maven-org.springframework:spring-expression-4.3.0.RELEASE Vulnerable Package
MEDIUM CVE-2022-22968 Maven-org.springframework:spring-context-4.3.0.RELEASE Vulnerable Package
MEDIUM CVE-2022-22970 Maven-org.springframework:spring-core-4.3.0.RELEASE Vulnerable Package
MEDIUM CVE-2022-22970 Maven-org.springframework:spring-beans-4.2.5.RELEASE Vulnerable Package
MEDIUM CVE-2022-22971 Maven-org.springframework:spring-core-4.3.0.RELEASE Vulnerable Package
MEDIUM CVE-2023-20861 Maven-org.springframework:spring-expression-4.3.0.RELEASE Vulnerable Package
MEDIUM CVE-2023-20863 Maven-org.springframework:spring-expression-4.3.0.RELEASE Vulnerable Package
MEDIUM Missing_HSTS_Header /BookDetail_jsp.java: 499 Attack Vector
MEDIUM Reflected_XSS_All_Clients /BookDetail_jsp.java: 173 Attack Vector
MEDIUM Reflected_XSS_All_Clients /BookDetail_jsp.java: 173 Attack Vector
MEDIUM Reflected_XSS_All_Clients /BookDetail_jsp.java: 173 Attack Vector
MEDIUM Reflected_XSS_All_Clients /BookDetail_jsp.java: 173 Attack Vector
MEDIUM Reflected_XSS_All_Clients /BookDetail_jsp.java: 173 Attack Vector
MEDIUM Reflected_XSS_All_Clients /BookDetail_jsp.java: 173 Attack Vector
MEDIUM Reflected_XSS_All_Clients /BookDetail_jsp.java: 173 Attack Vector
MEDIUM Stored_XSS /BookDetail_jsp.java: 54 Attack Vector
MEDIUM Stored_XSS /BookDetail_jsp.java: 61 Attack Vector
MEDIUM Unpinned Actions Full Length Commit SHA /main.yml: 21 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
LOW CVE-2020-9488 Maven-org.apache.logging.log4j:log4j-core-2.3 Vulnerable Package
LOW Cxeb68d52e-5509 Maven-commons-codec:commons-codec-1.11 Vulnerable Package
LOW Healthcheck Instruction Missing /Dockerfile: 33 Ensure that HEALTHCHECK is being used. The HEALTHCHECK instruction tells Docker how to test a container to check that it is still working
LOW Open_Redirect /BookDetail_jsp.java: 173 Attack Vector
LOW Open_Redirect /BookDetail_jsp.java: 173 Attack Vector
LOW Open_Redirect /BookDetail_jsp.java: 414 Attack Vector
LOW Use_Of_Hardcoded_Password_In_Config /.github/workflows/main.yml: 27 Attack Vector

Fixed Issues

Severity Issue Source File / Package
MEDIUM Missing_HSTS_Header /Backup/CardTypesGrid_jsp.java: 390

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant