Skip to content

Update README.md#15911

Open
cx-nitzan-massader wants to merge 3 commits intomasterfrom
NitzanMassAder-patch-4
Open

Update README.md#15911
cx-nitzan-massader wants to merge 3 commits intomasterfrom
NitzanMassAder-patch-4

Conversation

@cx-nitzan-massader
Copy link
Contributor

No description provided.

@cx-nitzan-massader
Copy link
Contributor Author

cx-nitzan-massader commented Nov 12, 2024

Logo
Checkmarx One – Scan Summary & Details0fb464cd-5208-42d7-bc12-cf59bf0974bd

New Issues (34)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
CRITICAL SQL_Injection /encode.frm: 42
detailsThe application's method executes an SQL query with openrecordset, at line 52 of /encode.frm. The application constructs this SQL query by embeddi...
Attack Vector
CRITICAL SQL_Injection /encode.frm: 41
detailsThe application's method executes an SQL query with openrecordset, at line 52 of /encode.frm. The application constructs this SQL query by embeddi...
Attack Vector
HIGH CVE-2015-2575 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: MySQL Connector/J before 5.1.35 is vulnerable to SQL Injection. The function quoteIdentifier() in the file src/com/mysql/jdbc/StringUtils.java does...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
HIGH CVE-2017-3523 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.40 and ea...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
HIGH CVE-2018-3258 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.12 and pr...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
HIGH Cx039cb67c-ead3 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: MySQL Connector/J before 5.1.37 is vulnerable to Memory Leak. The method methodCompressedInputStream.getNextPacketFromServer() of src/com/mysq/jdbc...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
HIGH Cx6f651376-312a Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: MySQL Connector/J before version 5.1.44 and 6.x is vulnerable to memory leak. When using cached server-side prepared statements, a memory leak occu...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
HIGH Cx7ef609d2-efb5 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: MySQL Connector/J before 5.1.31 is vulnerable to Memory Leak. Upon continuous interruption between the server and the database, the dead connection...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
HIGH Missing User Instruction /Dockerfile: 1
detailsA user should be specified in the dockerfile, otherwise the image will run as root
MEDIUM Add Instead of Copy /Dockerfile: 8
detailsUsing ADD to load external installation scripts could lead to an evil web server leveraging this and loading a malicious script.
MEDIUM Add Instead of Copy /Dockerfile: 7
detailsUsing ADD to load external installation scripts could lead to an evil web server leveraging this and loading a malicious script.
MEDIUM CVE-2017-3586 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and ea...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
MEDIUM CVE-2019-11358 Npm-jquery-3.2.1
detailsRecommended version: 3.5.0
Description: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollu...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
MEDIUM CVE-2019-2692 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.15 and pr...
Attack Vector: LOCAL
Attack Complexity: HIGH
Vulnerable Package
MEDIUM CVE-2020-11023 Npm-jquery-3.2.1
detailsRecommended version: 3.5.0
Description: In jQuery versions 1.0.3 through 3.4.1, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQu...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
MEDIUM CVE-2020-15250 Maven-junit:junit-4.10
detailsRecommended version: 4.13.1
Description: In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like sys...
Attack Vector: LOCAL
Attack Complexity: LOW
Vulnerable Package
MEDIUM CVE-2020-2875 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.14 and prior a...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
MEDIUM CVE-2020-2934 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.19 and prior a...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
MEDIUM CVE-2021-2471 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). This vulnerability affects versions through 8.0.26. Difficu...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
MEDIUM CVE-2022-21363 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. ...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
MEDIUM CVE-2024-34517 Maven-org.neo4j:neo4j-cypher-1.8.1
detailsRecommended version: 4.4.35
Description: The "Cypher" component in Neo4j versions prior to 5.19.0 mishandles IMMUTABLE privileges in some situations where an attacker already has admin acc...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
MEDIUM Hardcoded_password_in_Connection_String /encode.frm: 67
detailsThe application contains hardcoded connection details, ""connection string"", at line 67 of /encode.frm. This connection string contains a hardcode...
Attack Vector
MEDIUM Image Version Using 'latest' /Dockerfile: 1
detailsWhen building images, always tag them with useful tags which codify version information, intended destination (prod or test, for instance), stabili...
MEDIUM Parameter_Tampering /encode.frm: 65
detailsMethod at line 65 of /encode.frm gets user input from element text. This input is later concatenated by the application directly into a string var...
Attack Vector
MEDIUM Privacy_Violation /encode.frm: 42
detailsMethod at line 42 of /encode.frm sends user information outside the application. This may constitute a Privacy Violation.
Attack Vector
MEDIUM Privacy_Violation /encode.frm: 11
detailsMethod at line 11 of /encode.frm sends user information outside the application. This may constitute a Privacy Violation.
Attack Vector
MEDIUM Unpinned Package Version in Apk Add /Dockerfile: 1
detailsPackage version pinning reduces the range of versions that can be installed, reducing the chances of failure due to unanticipated changes
LOW CVE-2017-3589 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and ea...
Attack Vector: LOCAL
Attack Complexity: LOW
Vulnerable Package
LOW CVE-2020-2933 Maven-mysql:mysql-connector-java-5.1.18
detailsRecommended version: 8.0.28
Description: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 5.1.48 and prior. ...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
LOW Curl or Wget Instead of Add /Dockerfile: 7
detailsUse of Curl or Wget should be done instead of Add to fetch packages from remote URLs due to the use of Add being strongly discouraged
LOW Curl or Wget Instead of Add /Dockerfile: 8
detailsUse of Curl or Wget should be done instead of Add to fetch packages from remote URLs due to the use of Add being strongly discouraged
LOW Healthcheck Instruction Missing /Dockerfile: 1
detailsEnsure that HEALTHCHECK is being used. The HEALTHCHECK instruction tells Docker how to test a container to check that it is still working
LOW MAINTAINER Instruction Being Used /Dockerfile: 2
detailsThe MAINTAINER instruction sets the Author field of the generated images. The LABEL instruction is a much more flexible version of this and you sho...
LOW Multiple RUN, ADD, COPY, Instructions Listed /Dockerfile: 7
detailsMultiple commands (RUN, COPY, ADD) should be grouped in order to reduce the number of layers.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant