wasptree / verademo

A deliberately insecure Java web application
MIT License
1 stars 1 forks source link

Please sir, merge my code. #604

Open wasptree opened 2 years ago

github-actions[bot] commented 2 years ago



Scan Summary:
PIPELINE_SCAN_VERSION: 22.9.0-0
DEV-STAGE: DEVELOPMENT
SCAN_ID: 3dd23c59-f285-4fe5-8345-3885333fa0e4
SCAN_STATUS: SUCCESS
SCAN_MESSAGE: Scan successful. Results size: 345073 bytes
====================
Analysis Successful.
====================

===================
Analyzed 2 modules.
===================
verademo.war
JS files within verademo.war

====================
Analyzed 158 issues.
====================

details


-------------------------------------
Found 1 issues of Very High severity.
-------------------------------------
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'): com/veracode/verademo/controller/ToolsController.java:94
----------------------------------
Found 2 issues of Medium severity.
----------------------------------
CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS): com/veracode/verademo/controller/UserController.java:263
CWE-117: Improper Output Neutralization for Logs: com/veracode/verademo/controller/BlabController.java:559
**
Total flaws found: 158, New flaws found: 3 as compared to baseline
**

========================
FAILURE: Found 3 issues!
========================