quanted / cts_app

cts repo
3 stars 3 forks source link

App scan for kube stage deploy #212

Closed popenc closed 1 year ago

popenc commented 1 year ago

Creating an issue for this as a way to keep track.

popenc commented 1 year ago

Scan has passed with no high or critical level vulnerabilities. Note that this has passed despite the Prisma image scans returning vulnerabilities for Tomcat.

popenc commented 1 year ago

Waiting for API scan, I think?

popenc commented 1 year ago

API scan has returned 4 high level vulnerabilities. It's possible these are false positives, but some explicit user input sanitization will be added to ensure these vulnerabilities are resolved.

2022-11-22-ZAP-Report-CTS-API.pdf

popenc commented 1 year ago

Second scan has passed after adding the DOM sanitization.