Skip to content

Conversation

shiftleft-chuck
Copy link
Owner

No description provided.

@github-actions
Copy link

Neither source branch nor scan specified; switching to 'single' mode.

ShiftLeft LogoShiftLeft Logo

Checking analysis of application shiftleft-java-demo-220411 against 2 build rules.

Checking findings on scan 4.

Results per rule:

  • allow-zero-findings: FAIL (60 matched vulnerabilities; configured threshold is 0)

    First 5 findings:

    ID Severity Title
    257 critical Deserialization: Deserialization of attacker-controlled data via auth in AdminController.doPostLogin
    258 critical Deserialization: Deserialization of HTTP data via request in AdminController.doGetPrintSecrets
    259 critical Directory Traversal: HTTP data as file path via request in CustomerController.saveSettings
    260 critical Directory Traversal: HTTP data as file path via request in CustomerController.saveSettings
    261 critical Directory Traversal: HTTP data as file path via request in CustomerController.saveSettings
    Severity Count
    Critical 6
    Moderate 13
    Info 41
    Category Count
    Sensitive Data Usage 39
    XSS 9
    Header Injection 3
    Directory Traversal 3
    Security Best Practices 2
    Deserialization 2
    Remote Code Execution 1
    Session Injection 1
    OWASP Category Count
    A3-Sensitive-Data-Exposure 41
    A3-Cross-Site-Scripting 9
    A1-Injection 4
    A5-Broken-Access-Control 3
    A8-Deserialization 2
    A2-Broken-Authentication 1
  • reachable-oss-vuln: FAIL (46 matched vulnerabilities; configured threshold is 0)

    First 10 findings:

    ID Severity Title
    78 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    79 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    80 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    81 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    82 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    83 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    84 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    85 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    86 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    87 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    Severity Count
    Critical 40
    Moderate 6
    Info 0

2 rules failed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant