awshole / vulnerable-node

A very vulnerable web site written in NodeJS with the purpose of have a project with identified vulnerabilities to test the quality of security analyzers tools tools
Other
0 stars 0 forks source link

[CodeQL] Scan results (master) #1

Open github-actions[bot] opened 2 years ago

github-actions[bot] commented 2 years ago

Overview

CodeQL is the analysis engine used by developers to automate security checks, and by security researchers to perform variant analysis. In CodeQL, code is treated like data. Security vulnerabilities, bugs, and other errors are modeled as queries that can be executed against databases extracted from code. To learn more about CodeQL, see the documentation.

Summary of results

The following issues were identified. See additional details (including guidance on fixing issues) on the Security tab of this repository.

IssueSeverityOccurrences
Missing CSRF middlewareHigh1
Database query built from user-controlled sourcesHigh4
Client-side cross-site scriptingHigh3
Inefficient regular expressionHigh1
Hard-coded credentialsMedium1
Missing rate limitingMedium1
Clear text transmission of sensitive cookieMedium1
Server-side URL redirectMedium1
Unsafe expansion of self-closing HTML tagMedium2
DOM text reinterpreted as HTMLMedium6
Unsafe jQuery pluginMedium6
Polynomial regular expression used on uncontrolled dataMedium1
github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.

github-actions[bot] commented 2 years ago

A subsequent scan was executed.