Skip to content

Conversation

shiftleft-chuck
Copy link
Owner

No description provided.

@github-actions
Copy link

ShiftLeft LogoShiftLeft Logo

Checking analysis of application shiftleft-HSLGit-demo against 1 build rules.

Using sl version 0.9.1322 (3f862c2bf94418c30bd97c7ca0065d946d6938f3).

Checking findings on scan 1.

Results per rule:

  • allow-zero-findings: FAIL
    (84 matched vulnerabilities; configured threshold is 0).

    First 5 findings:

        ID   Severity   Title                                                                                                                            
     257   critical   Sensitive Data Leak: Security-sensitive Data Leaked to Console via firstName in CustomerController.debugEscaped              
     258   critical   Deserialization: External HTTP Data Used in Unsafe Deserialization Function via request in AdminController.doGetPrintSecrets 
     259   critical   Directory Traversal: HTTP Data as File Path via request in CustomerController.saveSettings                                   
     260   critical   Sensitive Data Leak: Sensitive Data is Leaked to Log in AccountController.depositIntoAccount                                   
     261   critical   Sensitive Data Leak: Sensitive Data is Leaked to Log in CustomerController.getCustomer                                         
     Severity   Count 
     Critical      20 
     Moderate      23 
     Info          41 
     Category                  Count 
     Sensitive Data Usage         39 
     Sensitive Data Leak          28 
     Cross-Site Scripting          9 
     Header Injection              3 
     Security Best Practices       2 
     Remote Code Execution         1 
     Directory Traversal           1 
     Deserialization               1 
     OWASP Category                Count 
     A3-Sensitive-Data-Exposure       69 
     A7-Xss                            9 
     A1-Injection                      4 
     A8-Insecure-Deserialization       1 
     A5-Broken-Access-Control          1 

1 rule failed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant