Skip to content

Conversation

@cx-pedro-lopes
Copy link
Contributor

Updates checkmarx-ast-cli to 2.3.15

Auto-generated by [create-pull-request][2]

@cx-ben-alvo
Copy link
Collaborator

cx-ben-alvo commented Feb 26, 2025

Logo
Checkmarx One – Scan Summary & Detailsc1cb75c9-4d71-4c33-ae55-91c471b0767a

New Issues (28)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
MEDIUM Input_Path_Not_Canonicalized /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 112
detailsMethod executeCommand at line 112 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets dynamic data from the get element. This element’s...
Attack Vector
MEDIUM Stored_Command_Injection /src/test/resources/python-vul-file.py: 56
detailsThe application's do_GET method calls an OS (shell) command with program, at line 57 of /src/test/resources/python-vul-file.py, using an untrusted ...
Attack Vector
MEDIUM Stored_Command_Injection /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 112
detailsThe application's buildProcess method calls an OS (shell) command with start, at line 148 of /src/main/java/com/checkmarx/ast/wrapper/Execution.jav...
Attack Vector
LOW Incorrect_Permission_Assignment_For_File_System_Resources /src/test/java/com/checkmarx/ast/RemediationTest.java: 12
detailsA file is created on the file system by path in /src/test/java/com/checkmarx/ast/RemediationTest.java at line 12 with potentially dangerous permiss...
Attack Vector
LOW Incorrect_Permission_Assignment_For_File_System_Resources /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 189
detailsA file is created on the file system by destination in /src/main/java/com/checkmarx/ast/wrapper/Execution.java at line 189 with potentially dangero...
Attack Vector
LOW Incorrect_Permission_Assignment_For_File_System_Resources /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 110
detailsA file is created on the file system by outputFile in /src/main/java/com/checkmarx/ast/wrapper/Execution.java at line 110 with potentially dangerou...
Attack Vector
LOW Information_Exposure_Through_an_Error_Message /src/main/java/com/checkmarx/ast/results/result/Node.java: 79
detailsMethod parse, at line 79 of /src/main/java/com/checkmarx/ast/results/result/Node.java, handles an Exception or runtime Error e. During the exceptio...
Attack Vector
LOW Information_Exposure_Through_an_Error_Message /src/main/java/com/checkmarx/ast/predicate/Predicate.java: 68
detailsMethod parse, at line 68 of /src/main/java/com/checkmarx/ast/predicate/Predicate.java, handles an Exception or runtime Error e. During the exceptio...
Attack Vector
LOW Information_Exposure_Through_an_Error_Message /src/main/java/com/checkmarx/ast/learnMore/LearnMore.java: 62
detailsMethod parse, at line 62 of /src/main/java/com/checkmarx/ast/learnMore/LearnMore.java, handles an Exception or runtime Error e. During the exceptio...
Attack Vector
LOW Information_Exposure_Through_an_Error_Message /src/main/java/com/checkmarx/ast/codebashing/CodeBashing.java: 57
detailsMethod parse, at line 57 of /src/main/java/com/checkmarx/ast/codebashing/CodeBashing.java, handles an Exception or runtime Error e. During the exce...
Attack Vector
LOW Information_Exposure_Through_an_Error_Message /src/main/java/com/checkmarx/ast/kicsRealtimeResults/KicsRealtimeResults.java: 49
detailsMethod parse, at line 49 of /src/main/java/com/checkmarx/ast/kicsRealtimeResults/KicsRealtimeResults.java, handles an Exception or runtime Error e....
Attack Vector
LOW Information_Exposure_Through_an_Error_Message /src/main/java/com/checkmarx/ast/remediation/KicsRemediation.java: 41
detailsMethod parse, at line 41 of /src/main/java/com/checkmarx/ast/remediation/KicsRemediation.java, handles an Exception or runtime Error e. During the ...
Attack Vector
LOW Information_Exposure_Through_an_Error_Message /src/main/java/com/checkmarx/ast/utils/JsonParser.java: 17
detailsMethod parse, at line 17 of /src/main/java/com/checkmarx/ast/utils/JsonParser.java, handles an Exception or runtime Error e. During the exception h...
Attack Vector
LOW Information_Exposure_Through_an_Error_Message /src/test/resources/python-vul-file.py: 71
detailsMethod do_GET, at line 71 of /src/test/resources/python-vul-file.py, handles an Exception or runtime Error ex. During the exception handling code, ...
Attack Vector
LOW Information_Exposure_Through_an_Error_Message /src/test/resources/python-vul-file.py: 72
detailsMethod do_GET, at line 72 of /src/test/resources/python-vul-file.py, handles an Exception or runtime Error format_exc. During the exception handlin...
Attack Vector
LOW Reversible_One_Way_Hash /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 38
detailsThe application is using a weak hashing primitive getInstance, in /src/main/java/com/checkmarx/ast/wrapper/Execution.java at line 209
Attack Vector
LOW Stored_Code_Injection /src/test/resources/python-vul-file.py: 56
detailsThe application's do_GET method receives and dynamically executes user-controlled code using exec, at line 57 of /src/test/resources/python-vul-fil...
Attack Vector
LOW Stored_Log_Forging /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 59
detailsMethod executeCommand at line 59 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets user input from element readLine. This element’s v...
Attack Vector
LOW Stored_Log_Forging /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 112
detailsMethod executeCommand at line 112 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets user input from element readAllBytes. This elemen...
Attack Vector
LOW Stored_Log_Forging /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 59
detailsMethod executeCommand at line 59 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets user input from element readLine. This element’s v...
Attack Vector
LOW Stored_Log_Forging /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 59
detailsMethod executeCommand at line 59 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets user input from element readLine. This element’s v...
Attack Vector
LOW Stored_Log_Forging /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 59
detailsMethod executeCommand at line 59 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets user input from element readLine. This element’s v...
Attack Vector
LOW Stored_Log_Forging /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 59
detailsMethod executeCommand at line 59 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets user input from element readLine. This element’s v...
Attack Vector
LOW Stored_Log_Forging /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 59
detailsMethod executeCommand at line 59 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets user input from element readLine. This element’s v...
Attack Vector
LOW Stored_Log_Forging /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 112
detailsMethod executeCommand at line 112 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets user input from element readAllBytes. This elemen...
Attack Vector
LOW Stored_Log_Forging /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 59
detailsMethod executeCommand at line 59 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets user input from element readLine. This element’s v...
Attack Vector
LOW Stored_Log_Forging /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 112
detailsMethod executeCommand at line 112 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets user input from element readAllBytes. This elemen...
Attack Vector
LOW Stored_Log_Forging /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 100
detailsMethod executeCommand at line 100 of /src/main/java/com/checkmarx/ast/wrapper/Execution.java gets user input from element readLine. This element’s ...
Attack Vector
Fixed Issues (3)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
MEDIUM Missing_HSTS_Header /src/test/resources/python-vul-file.py: 76
MEDIUM Missing_HSTS_Header /src/test/resources/python-vul-file.py: 76
MEDIUM Missing_HSTS_Header /src/test/resources/python-vul-file.py: 76

@cx-ben-alvo cx-ben-alvo merged commit 2b6cf21 into main Feb 26, 2025
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants