Skip to content

Update cx.yml#1

Open
cx-sean-carroll wants to merge 33 commits intomasterfrom
CxSeanC-patch-1
Open

Update cx.yml#1
cx-sean-carroll wants to merge 33 commits intomasterfrom
CxSeanC-patch-1

Conversation

@cx-sean-carroll
Copy link

No description provided.

@cx-sean-carroll
Copy link
Author

Logo
Checkmarx One – Scan Summary & Detailsbe7db1bf-9bf3-445e-a164-0d74d9c01bc7

New Issues

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2015-4852 Maven-commons-collections:commons-collections-3.2.1 Vulnerable Package
HIGH CVE-2015-7501 Maven-commons-collections:commons-collections-3.2.1 Vulnerable Package
HIGH CVE-2022-4492 Maven-io.undertow:undertow-core-2.0.9.Final Vulnerable Package
HIGH CVE-2022-45688 Maven-org.json:json-20131018 Vulnerable Package
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/ForgotPassword.jsp: 42 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/XPathQuery.java: 36 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/XPathQuery.java: 36 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/XPathQuery.java: 36 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/XPathQuery.java: 36 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/XPathQuery.java: 36 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/java/org/cysecurity/cspf/jvl/controller/XPathQuery.java: 36 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/admin/adminlogin.jsp: 12 Attack Vector
HIGH Side_Channel_Data_Leakage /src/main/webapp/login.jsp: 15 Attack Vector
MEDIUM RDS With Backup Disabled /rds.tf: 1 Make sure the AWS RDS configuration has automatic backup configured. If the retention period is equal to 0 there is no backup
MEDIUM Stored_Relative_Path_Traversal /src/main/webapp/vulnerability/sqli/download_id_union.jsp: 24 Attack Vector
MEDIUM Stored_Relative_Path_Traversal /src/main/webapp/vulnerability/sqli/download_id.jsp: 24 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/XPathQuery.java: 36 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/XPathQuery.java: 35 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/sqs.java: 25 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/csrf/changepassword.jsp: 33 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/Install.java: 60 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/Install.java: 58 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/Install.java: 58 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/changeCardDetails.jsp: 39 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/changeCardDetails.jsp: 38 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/changeCardDetails.jsp: 37 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/idor/change-email.jsp: 27 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/csrf/change-info.jsp: 26 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/sqli/download_id_union.jsp: 18 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/sqli/download_id.jsp: 18 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/myprofile.jsp: 16 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/myprofile.jsp: 16 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/UserDetails.jsp: 8 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/forum.jsp: 43 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/forum.jsp: 42 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/forum.jsp: 41 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/idor/change-email.jsp: 28 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/admin/manageusers.jsp: 13 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/admin/adminlogin.jsp: 11 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/forumposts.jsp: 9 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/ForgotPassword.jsp: 42 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/ForgotPassword.jsp: 42 Attack Vector
LOW Blind_SQL_Injections /src/main/webapp/vulnerability/DisplayMessage.jsp: 16 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/Register.java: 47 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 44 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/EmailCheck.java: 44 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/UsernameCheck.java: 43 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/Register.java: 46 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/Register.java: 45 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/Register.java: 44 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/Register.java: 43 Attack Vector
LOW Blind_SQL_Injections /src/main/java/org/cysecurity/cspf/jvl/controller/Register.java: 43 Attack Vector
LOW Heap_Inspection /src/main/webapp/vulnerability/Injection/orm.jsp: 31 Attack Vector
LOW Heap_Inspection /src/main/webapp/vulnerability/csrf/changepassword.jsp: 34 Attack Vector
LOW Heap_Inspection /src/main/java/org/cysecurity/cspf/jvl/model/DBConnect.java: 28 Attack Vector
LOW Heap_Inspection /src/main/java/org/cysecurity/cspf/jvl/controller/Install.java: 33 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/idor/download.jsp: 22 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/securitymisconfig/pages.jsp: 10 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/sqli/download_id.jsp: 41 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/admin/manageusers.jsp: 9 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/ForgotPassword.jsp: 39 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/DisplayMessage.jsp: 9 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/sqli/download_id.jsp: 21 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/admin/adminlogin.jsp: 10 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/csrf/change-info.jsp: 24 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/sqli/download_id_union.jsp: 21 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/admin/Configure.jsp: 22 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/myprofile.jsp: 14 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/UserDetails.jsp: 7 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/csrf/changepassword.jsp: 28 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/forumposts.jsp: 7 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/baasm/SiteTitle.jsp: 33 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/forum.jsp: 21 Attack Vector
LOW Improper_Resource_Shutdown_or_Release /src/main/webapp/vulnerability/forumUsersList.jsp: 7

More results are available on AST platform

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant