checkmarx-ltd / cx-flow

Checkmarx Scan and Result Orchestration
Apache License 2.0
88 stars 87 forks source link

Added latest committer email for JSON bug tracker #1301

Closed itsKedar closed 8 months ago

itsKedar commented 8 months ago

Description

Added latest committer email for JSON bug tracker

created a new Boolean JSON property latest-committer-email

AvivCx commented 8 months ago

Logo Checkmarx One – Scan Summary & Details95eff84b-febf-4874-918b-b656c48da7d2

New Issues

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2023-46589 Maven-org.apache.tomcat.embed:tomcat-embed-core-9.0.81 Vulnerable Package
HIGH CVE-2023-6378 Maven-ch.qos.logback:logback-core-1.2.10 Vulnerable Package
HIGH CVE-2023-6378 Maven-ch.qos.logback:logback-classic-1.2.10 Vulnerable Package
HIGH Passwords And Secrets - Generic Secret /gitlab-astcloud-sample.yml: 5 Query to find passwords and secrets in infrastructure code.
HIGH Passwords And Secrets - Generic Secret /gitlab-ast-sample.yml: 8 Query to find passwords and secrets in infrastructure code.
MEDIUM CVE-2023-34055 Maven-org.springframework.boot:spring-boot-2.7.14 Vulnerable Package
MEDIUM Unpinned Actions Full Length Commit SHA /wiki-publisher.yml: 16 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /release-drafter.yml: 13 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...

Fixed Issues

Severity Issue Source File / Package
HIGH Reflected_XSS_All_Clients /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 188
HIGH Reflected_XSS_All_Clients /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 111
MEDIUM Absolute_Path_Traversal /src/main/java/com/checkmarx/flow/controller/ADOController.java: 199
MEDIUM Absolute_Path_Traversal /src/main/java/com/checkmarx/flow/controller/ADOController.java: 199
MEDIUM Absolute_Path_Traversal /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 218
MEDIUM Absolute_Path_Traversal /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 208
MEDIUM Absolute_Path_Traversal /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 222
MEDIUM Absolute_Path_Traversal /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 222
MEDIUM Absolute_Path_Traversal /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 211
MEDIUM Absolute_Path_Traversal /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 211
MEDIUM Absolute_Path_Traversal /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 185
MEDIUM Absolute_Path_Traversal /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 185
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 188
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 111
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 188
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 111
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 107
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/ADOController.java: 199
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/cloud/BitbucketCloudController.java: 213
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/ADOController.java: 199
MEDIUM Unchecked_Input_for_Loop_Condition /src/main/java/com/checkmarx/flow/controller/GitLabController.java: 211
MEDIUM Unchecked_Input_for_Loop_Condition /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 251
LOW Log_Forging /src/main/java/com/checkmarx/flow/controller/GitLabController.java: 214
LOW Log_Forging /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 111