Skip to content

Conversation

shiftleft-chuck
Copy link
Owner

No description provided.

@github-actions
Copy link

ShiftLeft LogoShiftLeft Logo

Checking analysis of application shiftleft-java-demo against 2 build rules.

Using sl version 0.9.1290 (2b1b68134f56d1686e9cc960790e69c841ffb4d6).

Checking findings on scan 27.

Results per rule:

  • allow-zero-findings: FAIL
    (187 matched vulnerabilities; configured threshold is 0).

    First 5 findings:

       ID   Severity   CVE              Title                                                        
     70   critical   CVE-2018-1196    pkg:maven/org.springframework.boot/[email protected] 
     71   critical   CVE-2017-8046    pkg:maven/org.springframework.boot/[email protected] 
     76   critical   CVE-2019-10072   pkg:maven/org.apache.tomcat.embed/[email protected]   
     77   critical   CVE-2018-11784   pkg:maven/org.apache.tomcat.embed/[email protected]   
     78   critical   CVE-2019-12418   pkg:maven/org.apache.tomcat.embed/[email protected]   
     Severity   Count 
     Critical      54 
     Moderate      92 
     Info          41 
     Finding Type   Count 
     Oss_vuln         127 
     Vuln              60 
     Category                  Count 
     Sensitive Data Usage         39 
     Cross-Site Scripting          9 
     Header Injection              3 
     Directory Traversal           3 
     Security Best Practices       2 
     Deserialization               2 
     Session Injection             1 
     Remote Code Execution         1 
     OWASP Category               Count 
     A3-Sensitive-Data-Exposure      41 
     A3-Cross-Site-Scripting          9 
     A1-Injection                     4 
     A5-Broken-Access-Control         3 
     A8-Deserialization               2 
     A2-Broken-Authentication         1 
  • reachable-oss-vuln: FAIL
    (47 matched vulnerabilities; configured threshold is 0).

    First 10 findings:

       ID   Severity   CVE              Title                                                      
     76   critical   CVE-2019-10072   pkg:maven/org.apache.tomcat.embed/[email protected] 
     77   critical   CVE-2018-11784   pkg:maven/org.apache.tomcat.embed/[email protected] 
     78   critical   CVE-2019-12418   pkg:maven/org.apache.tomcat.embed/[email protected] 
     79   critical   CVE-2018-8034    pkg:maven/org.apache.tomcat.embed/[email protected] 
     80   critical   CVE-2019-17563   pkg:maven/org.apache.tomcat.embed/[email protected] 
     81   critical   CVE-2018-1305    pkg:maven/org.apache.tomcat.embed/[email protected] 
     82   critical   CVE-2018-8037    pkg:maven/org.apache.tomcat.embed/[email protected] 
     83   critical   CVE-2020-17527   pkg:maven/org.apache.tomcat.embed/[email protected] 
     84   critical   CVE-2019-0199    pkg:maven/org.apache.tomcat.embed/[email protected] 
     85   critical   CVE-2020-1935    pkg:maven/org.apache.tomcat.embed/[email protected] 
     Severity   Count 
     Critical      41 
     Moderate       6 
     Info           0 

2 rules failed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant