Skip to content

Conversation

@shiftleft-chuck
Copy link
Owner

No description provided.

@github-actions
Copy link

ShiftLeft LogoShiftLeft Logo

Checking analysis of application shiftleft-java-demo against 2 build rules.

Using sl version 0.9.1322 (3f862c2bf94418c30bd97c7ca0065d946d6938f3).

Checking findings on scan 37.

Results per rule:

  • allow-zero-findings: FAIL
    (185 matched vulnerabilities; configured threshold is 0).

    First 5 findings:

       ID   Severity   CVE              Title                                                        
     70   critical   CVE-2018-1196    pkg:maven/org.springframework.boot/[email protected] 
     71   critical   CVE-2017-8046    pkg:maven/org.springframework.boot/[email protected] 
     76   critical   CVE-2019-10072   pkg:maven/org.apache.tomcat.embed/[email protected]   
     77   critical   CVE-2018-11784   pkg:maven/org.apache.tomcat.embed/[email protected]   
     78   critical   CVE-2019-12418   pkg:maven/org.apache.tomcat.embed/[email protected]   
     Severity   Count 
     Critical      52 
     Moderate      92 
     Info          41 
     Finding Type   Count 
     Oss_vuln         127 
     Vuln              58 
     Category                  Count 
     Sensitive Data Usage         39 
     Cross-Site Scripting          9 
     Header Injection              3 
     Security Best Practices       2 
     Deserialization               2 
     Session Injection             1 
     Remote Code Execution         1 
     Directory Traversal           1 
     OWASP Category                Count 
     A3-Sensitive-Data-Exposure       41 
     A7-Xss                            9 
     A1-Injection                      4 
     A8-Insecure-Deserialization       2 
     A5-Broken-Access-Control          1 
     A2-Broken-Authentication          1 
  • reachable-oss-vuln: FAIL
    (47 matched vulnerabilities; configured threshold is 0).

    First 10 findings:

       ID   Severity   CVE              Title                                                      
     76   critical   CVE-2019-10072   pkg:maven/org.apache.tomcat.embed/[email protected] 
     77   critical   CVE-2018-11784   pkg:maven/org.apache.tomcat.embed/[email protected] 
     78   critical   CVE-2019-12418   pkg:maven/org.apache.tomcat.embed/[email protected] 
     79   critical   CVE-2018-8034    pkg:maven/org.apache.tomcat.embed/[email protected] 
     80   critical   CVE-2019-17563   pkg:maven/org.apache.tomcat.embed/[email protected] 
     81   critical   CVE-2018-1305    pkg:maven/org.apache.tomcat.embed/[email protected] 
     82   critical   CVE-2018-8037    pkg:maven/org.apache.tomcat.embed/[email protected] 
     83   critical   CVE-2020-17527   pkg:maven/org.apache.tomcat.embed/[email protected] 
     84   critical   CVE-2019-0199    pkg:maven/org.apache.tomcat.embed/[email protected] 
     85   critical   CVE-2020-1935    pkg:maven/org.apache.tomcat.embed/[email protected] 
     Severity   Count 
     Critical      41 
     Moderate       6 
     Info           0 

2 rules failed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants