Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding code with some deep sinks #1

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Adding code with some deep sinks

54cf77b
Select commit
Loading
Failed to load commit list.
Open

Adding code with some deep sinks #1

Adding code with some deep sinks
54cf77b
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / SonarCloudsquad-2 failed May 30, 2024 in 3s

4 new alerts including 3 high severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 3 high
  • 1 medium

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 22 in src/main/java/org/owasp/webgoat/lessons/vulnerablecomponents/DSAST.java

See this annotation in the file changed.

Code scanning / SonarCloudsquad-2

I/O function calls should not be vulnerable to path injection attacks High

Change this code to not construct the path from user-controlled data. See more on SonarCloud

Check failure on line 31 in src/main/java/org/owasp/webgoat/lessons/vulnerablecomponents/DSAST.java

See this annotation in the file changed.

Code scanning / SonarCloudsquad-2

I/O function calls should not be vulnerable to path injection attacks High

Change this code to not construct the path from user-controlled data. See more on SonarCloud

Check failure on line 38 in src/main/java/org/owasp/webgoat/lessons/vulnerablecomponents/DSAST.java

See this annotation in the file changed.

Code scanning / SonarCloudsquad-2

I/O function calls should not be vulnerable to path injection attacks High

Change this code to not construct the path from user-controlled data. See more on SonarCloud

Check warning on line 22 in src/main/java/org/owasp/webgoat/lessons/vulnerablecomponents/DSAST.java

See this annotation in the file changed.

Code scanning / SonarCloudsquad-2

Accessing files should not lead to filesystem oracle attacks Medium

Change this code to not construct the path from user-controlled data. See more on SonarCloud