Skip to content

Update README.md#2

Open
cx-sean-carroll wants to merge 1 commit intomasterfrom
matysiman-patch-13
Open

Update README.md#2
cx-sean-carroll wants to merge 1 commit intomasterfrom
matysiman-patch-13

Conversation

@cx-sean-carroll
Copy link

No description provided.

@cx-sean-carroll
Copy link
Author

Logo
Checkmarx One – Scan Summary & Details352e4627-c15d-4a92-9e9d-df85da05d3a8

New Issues

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2015-6420 Maven-commons-collections:commons-collections-3.2.1 Vulnerable Package
HIGH CVE-2016-2170 Maven-commons-collections:commons-collections-3.2.1 Vulnerable Package
HIGH CVE-2023-24998 Maven-org.apache.tomcat:tomcat-coyote-9.0.22 Vulnerable Package
HIGH CVE-2023-44487 Maven-org.apache.tomcat:tomcat-coyote-9.0.22 Vulnerable Package
HIGH CVE-2023-5072 Maven-org.json:json-20131018 Vulnerable Package
HIGH CVE-2023-5379 Maven-io.undertow:undertow-core-2.0.9.Final Vulnerable Package
HIGH Unsafe_Reflection /src/main/java/org/cysecurity/cspf/jvl/controller/Install.java: 55 Attack Vector
MEDIUM CVE-2023-42795 Maven-org.apache.tomcat:tomcat-util-9.0.22 Vulnerable Package
MEDIUM CVE-2023-42795 Maven-org.apache.tomcat:tomcat-coyote-9.0.22 Vulnerable Package
MEDIUM CVE-2023-45648 Maven-org.apache.tomcat:tomcat-coyote-9.0.22 Vulnerable Package
MEDIUM CVE-2024-1459 Maven-io.undertow:undertow-core-2.0.9.Final Vulnerable Package
MEDIUM CVE-2024-21733 Maven-org.apache.tomcat:tomcat-coyote-9.0.22 Vulnerable Package
MEDIUM Relative_Path_Traversal /src/main/java/org/cysecurity/cspf/jvl/controller/ForwardMe.java: 39 Attack Vector
MEDIUM Relative_Path_Traversal /src/main/java/org/cysecurity/cspf/jvl/controller/AddPage.java: 39 Attack Vector
MEDIUM Relative_Path_Traversal /src/main/webapp/vulnerability/sqli/download_id_union.jsp: 18 Attack Vector
MEDIUM Relative_Path_Traversal /src/main/webapp/vulnerability/sqli/download_id.jsp: 18 Attack Vector
MEDIUM Relative_Path_Traversal /src/main/webapp/vulnerability/sqli/download_id.jsp: 18 Attack Vector
MEDIUM Relative_Path_Traversal /src/main/webapp/vulnerability/sqli/download_id_union.jsp: 18 Attack Vector
MEDIUM Relative_Path_Traversal /src/main/webapp/vulnerability/idor/download.jsp: 11 Attack Vector
MEDIUM Unpinned Actions Full Length Commit SHA /cx.yml: 13 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
LOW IAM Access Analyzer Not Enabled /Unsecure_Sensitive_data.tf: 1 IAM Access Analyzer should be enabled and configured to continuously monitor resource permissions

Fixed Issues

Severity Issue Source File / Package
HIGH Cx6a5f7948-7054 Maven-commons-collections:commons-collections-3.2.1
HIGH HTTP Port Open To Internet /AJP_Open_Port.tf: 1
HIGH Passwords And Secrets - Generic Password /docker-compose.yml: 11
HIGH Remote Desktop Port Open To Internet /AJP_Open_Port.tf: 1
HIGH Security Group With Unrestricted Access To SSH /AJP_Open_Port.tf: 11
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Sensitive Port Is Exposed To Entire Network /AJP_Open_Port.tf: 6
HIGH Unknown Port Exposed To Internet /AJP_Open_Port.tf: 11
HIGH Unrestricted Security Group Ingress /AJP_Open_Port.tf: 11
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 12
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 12
MEDIUM CSRF /src/main/webapp/admin/adminlogin.jsp: 11
MEDIUM CSRF /src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java: 43
MEDIUM SQL Analysis Services Port 2383 (TCP) Is Publicly Accessible /AJP_Open_Port.tf: 6
LOW IAM Access Analyzer Not Enabled /AJP_Open_Port.tf: 1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants