Skip to content

Conversation

@shiftleft-chuck
Copy link
Owner

No description provided.

@github-actions
Copy link

github-actions bot commented Jun 7, 2022

ShiftLeft LogoShiftLeft Logo

Checking analysis of application shiftleft-HSLGit-demo against 2 build rules.

Using sl version 0.9.1338 (97324d6cd1ec050e03dd13314c4f303c7e630865).

Checking findings on scan 3.

Results per rule:

  • allow-zero-findings: FAIL
    (214 matched vulnerabilities; configured threshold is 0).

    First 5 findings:

       ID   Severity   CVE              Title                                                                    
     70   critical   CVE-2022-22965   pkg:maven/org.springframework.boot/spring-boot-starter-web@1.5.1.RELEASE 
     71   critical   GMS-2022-560     pkg:maven/org.springframework.boot/spring-boot-starter-web@1.5.1.RELEASE 
     72   critical   CVE-2018-1196    pkg:maven/org.springframework.boot/spring-boot@1.5.1.RELEASE             
     73   critical   CVE-2017-8046    pkg:maven/org.springframework.boot/spring-boot@1.5.1.RELEASE             
     74   critical   CVE-2022-27772   pkg:maven/org.springframework.boot/spring-boot@1.5.1.RELEASE             
     Severity   Count 
     Critical      77 
     Moderate      96 
     Info          41 
     Finding Type   Count 
     Oss_vuln         129 
     Vuln              85 
     Category                  Count 
     Sensitive Data Usage         39 
     Sensitive Data Leak          28 
     Cross-Site Scripting         10 
     Header Injection              3 
     Security Best Practices       2 
     Remote Code Execution         1 
     Directory Traversal           1 
     Deserialization               1 
     OWASP Category                Count 
     A3-Sensitive-Data-Exposure       69 
     A7-Xss                           10 
     A1-Injection                      4 
     A8-Insecure-Deserialization       1 
     A5-Broken-Access-Control          1 
  • reachable-oss-vuln: FAIL
    (49 matched vulnerabilities; configured threshold is 0).

    First 10 findings:

       ID   Severity   CVE              Title                                                      
     79   critical   CVE-2019-10072   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     80   critical   CVE-2018-11784   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     81   critical   CVE-2019-12418   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     82   critical   CVE-2018-8034    pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     83   critical   CVE-2019-17563   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     84   critical   CVE-2018-1305    pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     85   critical   CVE-2018-8037    pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     86   critical   CVE-2020-17527   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     87   critical   CVE-2019-0199    pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     88   critical   CVE-2020-1935    pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     Severity   Count 
     Critical      43 
     Moderate       6 
     Info           0 

2 rules failed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants