checkmarx-ltd / cx-flow

Checkmarx Scan and Result Orchestration
Apache License 2.0
88 stars 87 forks source link

Added code for brancehed scan project #1381

Closed satyamchaurasiapersistent closed 1 month ago

satyamchaurasiapersistent commented 1 month ago

By submitting a PR to this repository, you agree to the terms within the Checkmarx Code of Conduct. Please see the contributing guidelines for how to create and submit a high-quality PR for this repo.

Description

Describe the purpose of this PR along with any background information and the impacts of the proposed change.

References

Include supporting link to GitHub Issue/PR number

Testing

Describe how this change was tested. Be specific about anything not tested and reasons why. If this solution has unit and/or integration testing, tests should be added for new functionality and existing tests should complete without errors.

Please include any manual steps for testing end-to-end or functionality not covered by unit/integration tests.

Checklist

AvivCx commented 1 month ago

Logo Checkmarx One – Scan Summary & Details2381b8fb-cd4b-4c8c-b800-fccfc0d9030b

New Issues

Severity Issue Source File / Package Checkmarx Insight
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/ADOController.java: 202 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/ADOController.java: 199 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/ADOController.java: 58 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 83 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/TfsController.java: 55 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 218 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 208 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/cloud/BitbucketCloudController.java: 211 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 107 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 222 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 211 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 188 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 111 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 185 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 94 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 257 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 438 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 442 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 443 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 83 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 218 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/cloud/BitbucketCloudController.java: 211 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 208 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 107 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 222 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 211 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 188 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 111 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 185 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 83 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 83 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 83 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitLabController.java: 66 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitLabController.java: 211 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 83 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 83 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 83 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 83 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72 Attack Vector
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75 Attack Vector

Fixed Issues

Severity Issue Source File / Package
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/ADOController.java: 199
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/ADOController.java: 58
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 218
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 208
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 107
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 222
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 72
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/FlowController.java: 75
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 211
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 188
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 111
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 185
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitLabController.java: 66
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitLabController.java: 211
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/cloud/BitbucketCloudController.java: 211
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 218
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 208
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 107
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 222
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 211
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 188
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/postwebhook/PostWebhookController.java: 111
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/server/BitbucketServerController.java: 185
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 438
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitLabController.java: 66
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 257
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 94
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/bitbucket/cloud/BitbucketCloudController.java: 211
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/ADOController.java: 58
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/ADOController.java: 199
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 442
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 443
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitLabController.java: 211
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 94
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 257
MEDIUM SSRF /src/main/java/com/checkmarx/flow/controller/GitHubController.java: 438
MEDIUM SSRF

More results are available on AST platform