Skip to content

Conversation

@shiftleft-chuck
Copy link
Owner

No description provided.

@github-actions
Copy link

ShiftLeft LogoShiftLeft Logo

Checking analysis of application shiftleft-java-demo against 2 build rules.

Using sl version 0.9.1254 (d701df3323055d3e9349935b3f5d38f382b962f4).

Checking new findings between scans 17 and 18.

Results per rule:

  • allow-zero-findings: FAIL (2 matched vulnerabilities; configured threshold is 0)

    New findings:

    ID Severity Title
    291 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    292 critical Deserialization: Attacker-controlled Data Used in Unsafe Deserialization Function via auth in AdminController.doPostLogin
    Severity Count
    Critical 2
    Moderate 0
    Info 0
    Finding Type Count
    Vuln 1
    Secret 0
    Insight 0
    Extscan 0
    Oss_vuln 1
    Container 0
    Package 0
  • reachable-oss-vuln: FAIL (1 matched vulnerabilities; configured threshold is 0)

    New findings:

    ID Severity Title
    291 critical pkg:maven/org.apache.tomcat.embed/[email protected]
    Severity Count
    Critical 1
    Moderate 0
    Info 0

2 rules failed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants