|
| 1 | +<?xml version="1.0" encoding="UTF-8"?><record_update table="scan_table_check"> |
| 2 | + <scan_table_check action="INSERT_OR_UPDATE"> |
| 3 | + <active>true</active> |
| 4 | + <advanced>false</advanced> |
| 5 | + <category>security</category> |
| 6 | + <conditions table="sys_script_include">active=true^client_callable=true^scriptLIKEnew GlideRecord(^ORscriptLIKEnew GlideRecord (^EQ<item endquery="false" field="active" goto="false" newquery="false" operator="=" or="false" value="true"/> |
| 7 | + <item endquery="false" field="client_callable" goto="false" newquery="false" operator="=" or="false" value="true"/> |
| 8 | + <item endquery="false" field="script" goto="false" newquery="false" operator="LIKE" or="false" value="new GlideRecord("/> |
| 9 | + <item endquery="false" field="script" goto="false" newquery="false" operator="LIKE" or="true" value="new GlideRecord ("/> |
| 10 | + <item endquery="true" field="" goto="false" newquery="false" operator="=" or="false" value=""/> |
| 11 | + </conditions> |
| 12 | + <description>Using GlideRecord API in Client Callable Script Include for database query exposes data security risk</description> |
| 13 | + <documentation_url>https://docs.servicenow.com/bundle/utah-api-reference/page/script/server-scripting/concept/c_ScriptIncludes.html#title_client-callable-script-includes</documentation_url> |
| 14 | + <finding_type>scan_finding</finding_type> |
| 15 | + <name>Use GlideRecordSecure instead of GlideRecord API for CCSI</name> |
| 16 | + <priority>2</priority> |
| 17 | + <resolution_details>Use GlideRecordSecure API to ensure the security checks are performed and unauthorized access of data is prevented as it will automatically enforce ACLs.</resolution_details> |
| 18 | + <run_condition/> |
| 19 | + <score_max>100</score_max> |
| 20 | + <score_min>0</score_min> |
| 21 | + <score_scale>1</score_scale> |
| 22 | + <script><![CDATA[(function (engine) { |
| 23 | +
|
| 24 | + // Add your code here |
| 25 | +
|
| 26 | +})(engine);]]></script> |
| 27 | + <short_description>Use GlideRecordSecure instead of GlideRecord API for Client Callable Script Inc</short_description> |
| 28 | + <sys_class_name>scan_table_check</sys_class_name> |
| 29 | + <sys_created_by>admin</sys_created_by> |
| 30 | + <sys_created_on>2023-10-10 19:52:19</sys_created_on> |
| 31 | + <sys_id>076448b12ffd311002eb2ca62799b628</sys_id> |
| 32 | + <sys_mod_count>3</sys_mod_count> |
| 33 | + <sys_name>Use GlideRecordSecure instead of GlideRecord API for CCSI</sys_name> |
| 34 | + <sys_package display_value="Example Instance Checks" source="x_appe_exa_checks">ca8467c41b9abc10ce0f62c3b24bcbaa</sys_package> |
| 35 | + <sys_policy/> |
| 36 | + <sys_scope display_value="Example Instance Checks">ca8467c41b9abc10ce0f62c3b24bcbaa</sys_scope> |
| 37 | + <sys_update_name>scan_table_check_076448b12ffd311002eb2ca62799b628</sys_update_name> |
| 38 | + <sys_updated_by>admin</sys_updated_by> |
| 39 | + <sys_updated_on>2023-10-11 13:38:32</sys_updated_on> |
| 40 | + <table>sys_script_include</table> |
| 41 | + <use_manifest>false</use_manifest> |
| 42 | + </scan_table_check> |
| 43 | +</record_update> |
0 commit comments