pentaho / pentaho-platform

Pentaho BA Server Core
http://www.pentaho.com
Other
473 stars 723 forks source link

[SP-6628] backporting PPP-4174 Migrate axis2 web services to jax-rs and remove axis2 #5792

Closed srallapa closed 1 week ago

hitachivantarasonarqube[bot] commented 1 week ago

Quality Gate passed Quality Gate passed

Issues
0 New issues
69 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarQube

buildguy commented 1 week ago
[![🚨 Frogbot scanned this pull request and found the below:](https://raw.githubusercontent.com/jfrog/frogbot/master/resources/v2/vulnerabilitiesBannerPR.png)](https://docs.jfrog-applications.jfrog.io/jfrog-applications/frogbot)

📦 Vulnerable Dependencies

✍️ Summary

| SEVERITY | DIRECT DEPENDENCIES | IMPACTED DEPENDENCY | FIXED VERSIONS | CVES | | :---------------------: | :-----------------------------------: | :-----------------------------------: | :-----------------------------------: | :-----------------------------------: | | ![](https://raw.githubusercontent.com/jfrog/frogbot/master/resources/v2/applicableHighSeverity.png)
High | jdom:jdom:1.0
pentaho:pentaho-platform-extensions:10.2.0.0-SNAPSHOT | jdom:jdom 1.0 | - | CVE-2021-33813 |

🔬 Research Details

Description: An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

Note: ---
**Frogbot** also supports **Contextual Analysis, Secret Detection, IaC and SAST Vulnerabilities Scanning**. This features are included as part of the [JFrog Advanced Security](https://jfrog.com/advanced-security) package, which isn't enabled on your system.

[🐸 JFrog Frogbot](https://docs.jfrog-applications.jfrog.io/jfrog-applications/frogbot)
buildguy commented 1 week ago

:x: Build failed in 42m 47s

Build command:

mvn clean verify -B -e -Daudit -Djs.no.sandbox

:ok_hand: All tests passed!

Tests run: 2724, Failures: 0, Skipped: 5    Test Results


:information_source: This is an automatic message