Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

empty PR #835

Closed
wants to merge 1 commit into from
Closed

empty PR #835

wants to merge 1 commit into from

Conversation

miryamfoiferCX
Copy link
Contributor

By submitting a PR to this repository, you agree to the terms within the Checkmarx Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

Describe the purpose of this PR along with any background information and the impacts of the proposed change.

References

Include supporting link to GitHub Issue/PR number

Testing

Describe how this change was tested. Be specific about anything not tested and reasons why. If this solution has unit and/or integration testing, tests should be added for new functionality and existing tests should complete without errors.

Please include any manual steps for testing end-to-end or functionality not covered by unit/integration tests.

Checklist

  • I have added documentation for new/changed functionality in this PR (if applicable).
  • I have updated the CLI help for new/changed functionality in this PR (if applicable).
  • All active GitHub checks for tests, formatting, and security are passing
  • The correct base branch is being used

@OrShamirCM OrShamirCM requested a review from a team August 19, 2024 06:25
@miryamfoiferCX
Copy link
Contributor Author

miryamfoiferCX commented Aug 19, 2024

Logo
Checkmarx One – Scan Summary & Details44907961-0230-4002-9843-253342376ea0

Fixed Issues

Severity Issue Source File / Package
HIGH CVE-2022-36085 Go-github.com/open-policy-agent/opa-v0.42.2
HIGH CVE-2023-47108 Go-go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc-v0.45.0
HIGH Code_Injection /test/integration/data/python-vul-file.py: 24
HIGH Code_Injection /internal/commands/data/python-vul-file.py: 24
HIGH Code_Injection /test/integration/data/python-vul-file.py: 24
HIGH Code_Injection /internal/commands/data/python-vul-file.py: 24
HIGH Code_Injection /test/integration/data/python-vul-file.py: 55
HIGH Code_Injection /internal/commands/data/python-vul-file.py: 55
HIGH Command_Injection /test/integration/data/python-vul-file.py: 24
HIGH Command_Injection /test/integration/data/python-vul-file.py: 24
HIGH Command_Injection /test/integration/data/python-vul-file.py: 55
HIGH Command_Injection /internal/commands/data/python-vul-file.py: 24
HIGH Command_Injection /internal/commands/data/python-vul-file.py: 24
HIGH Command_Injection /internal/commands/data/python-vul-file.py: 55
HIGH Cx8bc4df28-fcf5 Npm-debug-4.3.6
HIGH Cx8bc4df28-fcf5 Npm-debug-4.3.4
HIGH Cxb3ca64d2-9cd1 Npm-mocha-10.0.0
HIGH Cxb6dee8d5-b814 Go-gopkg.in/square/go-jose.v2-v2.6.0
HIGH Cxdca8e59f-8bfe Npm-inflight-1.0.6
HIGH Cxf6e7f2c1-dc59 Npm-yauzl-2.10.0
HIGH Stored_XSS /internal/commands/data/python-vul-file.py: 36
HIGH Stored_XSS /test/integration/data/python-vul-file.py: 36
HIGH Stored_XSS /internal/commands/data/python-vul-file.py: 25
HIGH Stored_XSS /test/integration/data/python-vul-file.py: 25
HIGH Stored_XSS /internal/commands/data/python-vul-file.py: 34
HIGH Stored_XSS /test/integration/data/python-vul-file.py: 34
MEDIUM CVE-2019-25210 Go-helm.sh/helm/v3-v3.15.2
MEDIUM CVE-2023-0842 Npm-xml2js-0.4.23
MEDIUM CVE-2023-49559 Go-github.com/vektah/gqlparser/v2-v2.4.5
MEDIUM CVE-2024-0406 Go-github.com/mholt/archiver/v3-v3.5.1
MEDIUM CVE-2024-28122 Go-github.com/lestrrat-go/jwx-v1.2.28
MEDIUM CVE-2024-4067 Npm-micromatch-4.0.7
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/wrappers/client.go: 495
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/wrappers/client.go: 495
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/wrappers/codebashing-http.go: 62
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/wrappers/codebashing-http.go: 62
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/wrappers/client.go: 572
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/wrappers/client.go: 580
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/wrappers/client.go: 580
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/wrappers/client.go: 369
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/wrappers/client.go: 369
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/wrappers/bitbucketserver/bitbucket-server-http.go: 165
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/services/osinstaller/windows-utils.go: 21
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/services/osinstaller/windows-utils.go: 21
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/wrappers/bitbucketserver/bitbucket-server-http.go: 165
MEDIUM Denial_Of_Service_Resource_Exhaustion /internal/commands/scan.go: 1470
MEDIUM Insecure_Credential_Storage_Mechanism /internal/commands/auth.go: 146
MEDIUM Insecure_Credential_Storage_Mechanism /internal/commands/auth.go: 146
MEDIUM Insecure_Credential_Storage_Mechanism /internal/params/flags.go: 74
MEDIUM Insecure_Credential_Storage_Mechanism /internal/wrappers/auth-http.go: 30
MEDIUM Insecure_Credential_Storage_Mechanism /internal/params/flags.go: 74
MEDIUM Insecure_Credential_Storage_Mechanism /internal/commands/util/usercount/bitbucket.go: 116
MEDIUM Insecure_Credential_Storage_Mechanism /internal/commands/util/usercount/bitbucket.go: 177
MEDIUM Insecure_Credential_Storage_Mechanism /internal/commands/util/usercount/bitbucket.go: 34
MEDIUM Insecure_Credential_Storage_Mechanism /internal/wrappers/bitbucketserver/bitbucket-server-http.go: 113
MEDIUM Insecure_Credential_Storage_Mechanism /internal/wrappers/bitbucketserver/bitbucket-server-http.go: 89
MEDIUM Insecure_Credential_Storage_Mechanism /internal/wrappers/bitbucketserver/bitbucket-server-http.go: 54
MEDIUM Insecure_Credential_Storage_Mechanism /internal/commands/util/usercount/bitbucket.go: 116
MEDIUM Insecure_Credential_Storage_Mechanism /internal/commands/util/usercount/bitbucket.go: 177
MEDIUM Insecure_Credential_Storage_Mechanism /internal/commands/util/usercount/bitbucket.go: 34
MEDIUM Insecure_Credential_Storage_Mechanism /internal/wrappers/bitbucketserver/bitbucket-server-http.go: 113
MEDIUM Insecure_Credential_Storage_Mechanism /internal/wrappers/bitbucketserver/bitbucket-server-http.go: 89
MEDIUM Insecure_Credential_Storage_Mechanism /internal/wrappers/bitbucketserver/bitbucket-server-http.go: 54
MEDIUM Missing_HSTS_Header /internal/commands/data/python-vul-file.py: 75
MEDIUM Missing_HSTS_Header /internal/commands/data/python-vul-file.py: 75
MEDIUM Reflected_Absolute_Path_Traversal /internal/wrappers/client.go: 580
MEDIUM Reflected_Absolute_Path_Traversal /internal/wrappers/client.go: 580
MEDIUM Reflected_Absolute_Path_Traversal /internal/wrappers/client.go: 580
MEDIUM Reflected_Relative_Path_Traversal /internal/wrappers/client.go: 580
MEDIUM Reflected_Relative_Path_Traversal /internal/wrappers/client.go: 580
MEDIUM Reflected_Relative_Path_Traversal /internal/wrappers/client.go: 580
MEDIUM SSRF /internal/wrappers/client.go: 572
MEDIUM SSRF /internal/wrappers/client.go: 373
MEDIUM SSRF /internal/wrappers/client.go: 624
MEDIUM Stored_Absolute_Path_Traversal /internal/wrappers/ntlm/proxy-ntml.go: 185
MEDIUM Stored_Absolute_Path_Traversal /internal/wrappers/client.go: 563
MEDIUM Stored_Absolute_Path_Traversal /internal/wrappers/ntlm/proxy-ntml.go: 185
MEDIUM Stored_Absolute_Path_Traversal /internal/services/osinstaller/windows-utils.go: 21
MEDIUM Stored_Absolute_Path_Traversal /internal/services/osinstaller/windows-utils.go: 21
MEDIUM Stored_Absolute_Path_Traversal /internal/commands/scan.go: 1470
MEDIUM Stored_Absolute_Path_Traversal /internal/commands/scan.go: 1470
MEDIUM Stored_Absolute_Path_Traversal /internal/commands/scan.go: 1470
MEDIUM Stored_Command_Injection /internal/commands/data/python-vul-file.py: 55
MEDIUM Stored_Command_Injection /test/integration/data/python-vul-file.py: 55
MEDIUM Stored_Relative_Path_Traversal /internal/wrappers/ntlm/proxy-ntml.go: 185
MEDIUM Stored_Relative_Path_Traversal /internal/wrappers/client.go: 563
MEDIUM Stored_Relative_Path_Traversal /internal/wrappers/ntlm/proxy-ntml.go: 185
MEDIUM Stored_Relative_Path_Traversal /internal/services/osinstaller/windows-utils.go: 21
MEDIUM Stored_Relative_Path_Traversal /internal/services/osinstaller/windows-utils.go: 21
MEDIUM Stored_Relative_Path_Traversal /internal/commands/scan.go: 1470
MEDIUM Stored_Relative_Path_Traversal /internal/commands/scan.go: 1470
MEDIUM Stored_Relative_Path_Traversal /internal/commands/scan.go: 1470

@miryamfoiferCX miryamfoiferCX deleted the mirymfFoifer/emptyPR branch August 20, 2024 05:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant