Skip to content

GHAS Summary Report - Sun May 18 2025 #134

@octofelickz-ghas-metrics-report

Description

GHAS Metrics Summary


Repository octofelickz/dvcsharp-api

Dependabot

  • Open Alerts: 31
  • Fixed in the past X days: 0
  • Opened in the past X days: 0
  • Frequency: daily
  • MTTR:
  • MTTD:

Dependabot - top 10

PackageSeverityVulnerable versionsPatched versionCVECVSSLink
System.Text.Encodings.Webcritical>= 4.0.0, < 4.5.14.5.1CVE-2021-26701CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:Hhttps://github.com/octofelickz/dvcsharp-api/security/dependabot/7
Microsoft.NETCore.Apphigh>= 1.0.0, < 2.0.32.0.3CVE-2017-11770CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:Hhttps://github.com/octofelickz/dvcsharp-api/security/dependabot/31
System.Text.RegularExpressionshigh>= 4.3.0, < 4.3.14.3.1CVE-2019-0820CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:Hhttps://github.com/octofelickz/dvcsharp-api/security/dependabot/30
System.Net.Httphigh< 4.3.44.3.4CVE-2018-8292CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:Nhttps://github.com/octofelickz/dvcsharp-api/security/dependabot/29
System.Net.Securityhigh= 4.3.04.3.1CVE-2017-0249CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:Lhttps://github.com/octofelickz/dvcsharp-api/security/dependabot/27
System.Net.Securityhigh= 4.3.04.3.1CVE-2017-0247CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:Nhttps://github.com/octofelickz/dvcsharp-api/security/dependabot/26
System.Data.SqlClienthigh< 4.8.64.8.6CVE-2024-0056CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:Nhttps://github.com/octofelickz/dvcsharp-api/security/dependabot/23
Microsoft.AspNetCore.Server.Kestrel.Transport.Libuvhigh<= 2.1.392.1.40CVE-2023-38180CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:Hhttps://github.com/octofelickz/dvcsharp-api/security/dependabot/21
Microsoft.AspNetCore.Identityhigh< 2.1.392.1.39CVE-2023-33170CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:Hhttps://github.com/octofelickz/dvcsharp-api/security/dependabot/20
Newtonsoft.Jsonhigh< 13.0.113.0.1CVE-2024-21907CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:Hhttps://github.com/octofelickz/dvcsharp-api/security/dependabot/18

Code Scanning

  • Open Alerts: 27
  • Fixed in the past X days: 5
  • Opened in the past X days: 0
  • Frequency: daily
  • MTTR: 32 days, 8 hours, 10 minutes, 50 seconds
  • MTTD:

Code Scanning - top 10

VulnerabilitySeverityWeaknessToolVulnerable fileLink
cs/xml/insecure-dtd-handlingcriticalCWE-611, CWE-776, CWE-827CodeQLControllers/ImportsController.cs#L29https://github.com/octofelickz/dvcsharp-api/security/code-scanning/4
cs/user-controlled-bypasshighCWE-247, CWE-350, CWE-807CodeQLControllers/AuthorizationsController.cs#L53https://github.com/octofelickz/dvcsharp-api/security/code-scanning/2
generic.secrets.security.detected-jwt-token.detected-jwt-tokenerrorCWE-321Semgrep OSSdocumentation-dvcsharp-book/data/DVCSharp_postman_v2.json#L141https://github.com/octofelickz/dvcsharp-api/security/code-scanning/27
generic.secrets.security.detected-jwt-token.detected-jwt-tokenerrorCWE-321Semgrep OSSdocumentation-dvcsharp-book/data/DVCSharp_postman_v2.json#L108https://github.com/octofelickz/dvcsharp-api/security/code-scanning/26
generic.secrets.security.detected-jwt-token.detected-jwt-tokenerrorCWE-321Semgrep OSSdocumentation-dvcsharp-book/data/DVCSharp_postman_v2.json#L73https://github.com/octofelickz/dvcsharp-api/security/code-scanning/25
generic.secrets.security.detected-jwt-token.detected-jwt-tokenerrorCWE-321Semgrep OSSdocumentation-dvcsharp-book/data/DVCSharp_postman_v2.json#L46https://github.com/octofelickz/dvcsharp-api/security/code-scanning/24
generic.secrets.security.detected-jwt-token.detected-jwt-tokenerrorCWE-321Semgrep OSSdocumentation-dvcsharp-book/attacks/ssrf.md#L30https://github.com/octofelickz/dvcsharp-api/security/code-scanning/23
generic.secrets.security.detected-jwt-token.detected-jwt-tokenerrorCWE-321Semgrep OSSdocumentation-dvcsharp-book/attacks/sso-cookie-auth-bypass.md#L29https://github.com/octofelickz/dvcsharp-api/security/code-scanning/22
generic.secrets.security.detected-jwt-token.detected-jwt-tokenerrorCWE-321Semgrep OSSdocumentation-dvcsharp-book/attacks/privilege-escalation.md#L20https://github.com/octofelickz/dvcsharp-api/security/code-scanning/21
generic.secrets.security.detected-generic-secret.detected-generic-secreterrorCWE-798Semgrep OSSdocumentation-dvcsharp-book/attacks/insecure-jwt-usage.md#L14https://github.com/octofelickz/dvcsharp-api/security/code-scanning/20

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions