Open mend-for-github-com[bot] opened 1 year ago
Latest Scan: 2024-03-05 02:41am Total Findings: 16 | New Findings: 16 | Resolved Findings: 16 Tested Project Files: 50 Detected Programming Languages: 1 (JavaScript / TypeScript*)
The list below presents the 10 most relevant findings that need your attention. To view information on the remaining findings, navigate to the Mend Application.
Code Security Report
Scan Metadata
Latest Scan: 2024-03-05 02:41am Total Findings: 16 | New Findings: 16 | Resolved Findings: 16 Tested Project Files: 50 Detected Programming Languages: 1 (JavaScript / TypeScript*)
Most Relevant Findings
Vulnerable Code
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/contributions.js#L28-L331 Data Flow/s detected
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L54 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/contributions.js#L28 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/contributions.js#L33Vulnerable Code
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/contributions.js#L27-L321 Data Flow/s detected
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L54 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/contributions.js#L28 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/contributions.js#L32Vulnerable Code
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/error.js#L5-L101 Data Flow/s detected
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L97 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/error.js#L3 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/error.js#L11 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/error.js#L10Vulnerable Code
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L60-L657 Data Flow/s detected
View Data Flow 1
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L50 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L40 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L45 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L69 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L65View Data Flow 2
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L50 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L40 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L44 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L68 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L65View Data Flow 3
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L50 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L40 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L46 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L70 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/profile.js#L65Vulnerable Code
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/contributions.js#L29-L341 Data Flow/s detected
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L54 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/contributions.js#L28 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/contributions.js#L34Vulnerable Code
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L83-L881 Data Flow/s detected
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L84 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L86 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L88Vulnerable Code
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/user-dao.js#L86-L911 Data Flow/s detected
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L36 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/session.js#L51 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/session.js#L53 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/session.js#L56 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/user-dao.js#L57 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/user-dao.js#L92 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/user-dao.js#L91Vulnerable Code
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/memos-dao.js#L18-L231 Data Flow/s detected
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L69 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/memos.js#L11 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/memos.js#L13 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/memos-dao.js#L15 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/memos-dao.js#L19 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/memos-dao.js#L23Vulnerable Code
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/research.js#L11-L161 Data Flow/s detected
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L94 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/research.js#L12 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/research.js#L15 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/research.js#L16Vulnerable Code
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/user-dao.js#L99-L1041 Data Flow/s detected
https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/index.js#L40 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/session.js#L183 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/session.js#L187 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/session.js#L200 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/session.js#L132 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/session.js#L200 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/routes/session.js#L202 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/user-dao.js#L103 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/user-dao.js#L105 https://github.com/DimaMend/NodeGoat/blob/b6cc31553629d120f2eb3b9d5e75b3ec3ebf7ece/app/data/user-dao.js#L104Findings Overview