Skip to content

Conversation

shiftleft-chuck
Copy link
Owner

No description provided.

@github-actions
Copy link

github-actions bot commented Jun 7, 2022

ShiftLeft LogoShiftLeft Logo

Checking analysis of application shiftleft-HSLGit-demo against 2 build rules.

Using sl version 0.9.1338 (97324d6cd1ec050e03dd13314c4f303c7e630865).

Checking findings on scan 3.

Results per rule:

  • allow-zero-findings: FAIL
    (214 matched vulnerabilities; configured threshold is 0).

    First 5 findings:

       ID   Severity   CVE              Title                                                                    
     70   critical   CVE-2022-22965   pkg:maven/org.springframework.boot/[email protected] 
     71   critical   GMS-2022-560     pkg:maven/org.springframework.boot/[email protected] 
     72   critical   CVE-2018-1196    pkg:maven/org.springframework.boot/[email protected]             
     73   critical   CVE-2017-8046    pkg:maven/org.springframework.boot/[email protected]             
     74   critical   CVE-2022-27772   pkg:maven/org.springframework.boot/[email protected]             
     Severity   Count 
     Critical      77 
     Moderate      96 
     Info          41 
     Finding Type   Count 
     Oss_vuln         129 
     Vuln              85 
     Category                  Count 
     Sensitive Data Usage         39 
     Sensitive Data Leak          28 
     Cross-Site Scripting         10 
     Header Injection              3 
     Security Best Practices       2 
     Remote Code Execution         1 
     Directory Traversal           1 
     Deserialization               1 
     OWASP Category                Count 
     A3-Sensitive-Data-Exposure       69 
     A7-Xss                           10 
     A1-Injection                      4 
     A8-Insecure-Deserialization       1 
     A5-Broken-Access-Control          1 
  • reachable-oss-vuln: FAIL
    (49 matched vulnerabilities; configured threshold is 0).

    First 10 findings:

       ID   Severity   CVE              Title                                                      
     79   critical   CVE-2019-10072   pkg:maven/org.apache.tomcat.embed/[email protected] 
     80   critical   CVE-2018-11784   pkg:maven/org.apache.tomcat.embed/[email protected] 
     81   critical   CVE-2019-12418   pkg:maven/org.apache.tomcat.embed/[email protected] 
     82   critical   CVE-2018-8034    pkg:maven/org.apache.tomcat.embed/[email protected] 
     83   critical   CVE-2019-17563   pkg:maven/org.apache.tomcat.embed/[email protected] 
     84   critical   CVE-2018-1305    pkg:maven/org.apache.tomcat.embed/[email protected] 
     85   critical   CVE-2018-8037    pkg:maven/org.apache.tomcat.embed/[email protected] 
     86   critical   CVE-2020-17527   pkg:maven/org.apache.tomcat.embed/[email protected] 
     87   critical   CVE-2019-0199    pkg:maven/org.apache.tomcat.embed/[email protected] 
     88   critical   CVE-2020-1935    pkg:maven/org.apache.tomcat.embed/[email protected] 
     Severity   Count 
     Critical      43 
     Moderate       6 
     Info           0 

2 rules failed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant