Skip to content

Update README.md #43

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Conversation

shiftleft-chuck
Copy link
Owner

No description provided.

@github-actions
Copy link

ShiftLeft LogoShiftLeft Logo

Checking analysis of application shiftleft-java-demo against 2 build rules.

Using sl version 0.9.1290 (2b1b68134f56d1686e9cc960790e69c841ffb4d6).

Checking findings on scan 26.

Results per rule:

  • allow-zero-findings: FAIL
    (187 matched vulnerabilities; configured threshold is 0).

    First 5 findings:

       ID   Severity   CVE              Title                                                        
     70   critical   CVE-2018-1196    pkg:maven/org.springframework.boot/spring-boot@1.5.1.RELEASE 
     71   critical   CVE-2017-8046    pkg:maven/org.springframework.boot/spring-boot@1.5.1.RELEASE 
     76   critical   CVE-2019-10072   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11   
     77   critical   CVE-2018-11784   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11   
     78   critical   CVE-2019-12418   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11   
     Severity   Count 
     Critical      54 
     Moderate      92 
     Info          41 
     Finding Type   Count 
     Oss_vuln         127 
     Vuln              60 
     Category                  Count 
     Sensitive Data Usage         39 
     Cross-Site Scripting          9 
     Header Injection              3 
     Directory Traversal           3 
     Security Best Practices       2 
     Deserialization               2 
     Session Injection             1 
     Remote Code Execution         1 
     OWASP Category               Count 
     A3-Sensitive-Data-Exposure      41 
     A3-Cross-Site-Scripting          9 
     A1-Injection                     4 
     A5-Broken-Access-Control         3 
     A8-Deserialization               2 
     A2-Broken-Authentication         1 
  • reachable-oss-vuln: FAIL
    (47 matched vulnerabilities; configured threshold is 0).

    First 10 findings:

       ID   Severity   CVE              Title                                                      
     76   critical   CVE-2019-10072   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     77   critical   CVE-2018-11784   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     78   critical   CVE-2019-12418   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     79   critical   CVE-2018-8034    pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     80   critical   CVE-2019-17563   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     81   critical   CVE-2018-1305    pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     82   critical   CVE-2018-8037    pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     83   critical   CVE-2020-17527   pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     84   critical   CVE-2019-0199    pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     85   critical   CVE-2020-1935    pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.11 
     Severity   Count 
     Critical      41 
     Moderate       6 
     Info           0 

2 rules failed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant