Custodela / Riches

0 stars 3 forks source link

Update buildspec.yml #302

Closed kmcdon83 closed 5 years ago

kmcdon83 commented 5 years ago

Scan submitted to Checkmarx

kmcdon83 commented 5 years ago

Checkmarx scan completed

Full Scan Details

Checkmarx Scan Summary

Severity Count
High 32
Medium 56
Low 328
Informational 4

Violation Summary

Severity Count
High 21

Details

Lines Severity Category File Link
101 102 104 105 106 107 High SQL_Injection riches/WEB-INF/src/java/com/checkmarx/samples/riches/restful/TransactionResources.java Checkmarx
20 High SQL_Injection riches/WEB-INF/src/java/com/checkmarx/samples/riches/Messages.java Checkmarx
11 High Stored_XSS riches/pages/Backup.jsp Checkmarx
82 102 141 62 High SQL_Injection riches/WEB-INF/src/java/com/checkmarx/samples/riches/restful/AccountResources.java Checkmarx
13 High Stored_XSS riches/pages/FilesViewer.jsp Checkmarx
Library Severity CVE
commons-collections:commons-collections High CVE-2015-7501
commons-fileupload:commons-fileupload High CVE-2016-1000031 CVE-2013-2186 CVE-2014-0050
dom4j:dom4j High CVE-2018-1000632
com.opensymphony:xwork High CVE-2015-5209 CVE-2016-4438 CVE-2013-1966 CVE-2017-9787 CVE-2016-4461 CVE-2017-9804 CVE-2018-11776 CVE-2016-0785 CVE-2013-2115 CVE-2013-1965 CVE-2012-0838 CVE-2012-0391 CVE-2014-0112
tomcat:jasper-runtime High CVE-2016-5018
struts:struts High CVE-2014-0114 CVE-2006-1547 CVE-2006-1546
taglibs:standard High CVE-2015-0254
commons-beanutils:commons-beanutils High CVE-2014-0114