Skip to content

Conversation

@cx-anurag-dalke
Copy link
Collaborator

Updates checkmarx-ast-cli to 2.3.40

Auto-generated by [create-pull-request][2]

@cx-ben-alvo
Copy link
Collaborator

Logo
Checkmarx One – Scan Summary & Details635d5478-1c32-4f4a-86dc-2fb8cf8c30f5

New Issues (11)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH Passwords And Secrets - Generic Password /release.yml: 105
detailsQuery to find passwords and secrets in infrastructure code.
ID: H0ivHBxkNH%2BEIA1eyvz9EEj%2BAgQ%3D
MEDIUM ALB Deletion Protection Disabled /positive1.tf: 15
detailsApplication Load Balancer should have deletion protection enabled
ID: zg1cBvbrhNLxVboSKpyjmWbqU9o%3D
MEDIUM ALB Listening on HTTP /positive1.tf: 9
detailsAWS Application Load Balancer (alb) should not listen on HTTP
ID: O8byoDsd3nmhEbCNco1oynLXWfE%3D
MEDIUM ALB Not Dropping Invalid Headers /positive1.tf: 15
detailsIt's considered a best practice when using Application Load Balancers to drop invalid header fields
ID: qvZPpWm8avYYv6GPvrCd92IvwhE%3D
MEDIUM CVE-2020-15250 Maven-junit:junit-4.10
detailsRecommended version: 4.13.1
Description: In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like sys...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: LZgv%2Fw1S60gFD%2BZDMmjIzsLjWfYWAmI%2B%2FCUK6IHGisc%3D
Vulnerable Package
MEDIUM ELBv2 LB Access Log Disabled /positive1.tf: 15
detailsELBv2 LBs should have access log enabled to capture detailed information about requests sent to your load balancer.
ID: SwXIeYCAhsKw6kNGc%2FMAQiV6EFM%3D
MEDIUM Reversible_One_Way_Hash /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 38
detailsThe application is using a weak hashing primitive getInstance, in /src/main/java/com/checkmarx/ast/wrapper/Execution.java at line 209
ID: a%2FNLACgFNKgn997xWUHIKiQzjos%3D
Attack Vector
LOW APT-GET Missing Flags To Avoid Manual Input /Dockerfile: 5
detailsCheck if apt-get calls use flags to avoid user manual input.
ID: jfZh0UJk7d3yZvWU%2BMZVe%2FotGh4%3D
LOW Healthcheck Instruction Missing /Dockerfile: 1
detailsEnsure that HEALTHCHECK is being used. The HEALTHCHECK instruction tells Docker how to test a container to check that it is still working
ID: pq3yqo20YibWk%2BA6WnaVJTu%2F1y0%3D
LOW IAM Access Analyzer Not Enabled /positive1.tf: 15
detailsIAM Access Analyzer should be enabled and configured to continuously monitor resource permissions
ID: %2FH6Qs2M8HFCNkyCsi7bGU2GDt4g%3D
LOW Shield Advanced Not In Use /positive1.tf: 15
detailsAWS Shield Advanced should be used for Amazon Route 53 hosted zone, AWS Global Accelerator accelerator, Elastic IP Address, Elastic Load Balancing,...
ID: LQfE6q%2BzH43A5RiXDxGr8C7Cu98%3D

Use @Checkmarx to reach out to us for assistance.

Just send a PR comment with @Checkmarx followed by a natural language request.

Examples: @Checkmarx how are you able to help me? @Checkmarx rescan this PR

@cx-anurag-dalke cx-anurag-dalke merged commit 52d9235 into main Nov 20, 2025
6 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants