Skip to content

Pull Request to add Qwiet preZero scans#14

Open
ongamse wants to merge 1 commit into
masterfrom
feature/qwiet-prezero
Open

Pull Request to add Qwiet preZero scans#14
ongamse wants to merge 1 commit into
masterfrom
feature/qwiet-prezero

Conversation

@ongamse
Copy link
Copy Markdown
Owner

@ongamse ongamse commented May 31, 2024

This automated PR was created by your AppSec team. ShiftLeft CORE is our preferred code analysis tool to continuously scan this application and open-source libraries for vulnerabilities.

Please contact the AppSec team should you require any additional information about this pull request or the ShiftLeft platform.

@github-actions
Copy link
Copy Markdown

Qwiet LogoQwiet Logo

Checking analysis of application Qwiet-python-GH against 3 build rules.

Using sl version 0.9.2509 (32315c47fd2cff75fe89e7cc80b6ac271119d689).

Checking findings on scan 2.

Results per rule:

  • Allow no critical findings: FAIL
    (3 matched vulnerabilities; configured threshold is 0).

    Findings:

       ID   CVSS    Rating    Title                                                                                     
     10    9.0   critical   Remote Code Execution: Command Injection Through Attacker-controlled Data in actions.py 
     11    9.0   critical   SQL Injection: Attacker-controlled Data Used in SQL Query in auth.py                    
     12    9.0   critical   SQL Injection: Attacker-controlled Data Used in SQL Query in users.py                   
     Severity rating   Count 
     Critical              3 
     High                  0 
     Medium                0 
     Low                   0 
     Category                Count 
     SQL Injection               2 
     Remote Code Execution       1 
  • Allow one OSS or container finding: FAIL
    (12 matched vulnerabilities; configured threshold is 1).

    First 5 findings:

       ID   CVSS    Rating    CVE                Title                                                                                                                                                    
     31    9.8   critical   CVE-2022-29361     Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request w…
     17    8.6     high     CVE-2016-10745     In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.                                                                                       
     19    8.6     high     CVE-2019-10906     In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.                                                                                
     13    7.5     high     CVE-2019-1010083   The Pallets Project Flask before 1.0 is affected by unexpected memory usage. The impact is denial of service. The attack vector is crafted encoded JSON …
     15    7.5     high     CVE-2023-30861     When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by a proxy to other…
     Severity rating   Count 
     Critical              1 
     High                  6 
     Medium                4 
     Low                   1 
     CVE                Count 
     CVE-2024-34069         1 
     CVE-2024-34064         1 
     CVE-2024-22195         1 
     CVE-2023-46136         1 
     CVE-2023-30861         1 
     CVE-2023-25577         1 
     CVE-2023-23934         1 
     CVE-2022-29361         1 
     CVE-2020-28493         1 
     CVE-2019-1010083       1 
     CVE-2019-10906         1 
     CVE-2016-10745         1 
  • Allow no reachable OSS vulnerability: pass
    (0 matched vulnerabilities; configured threshold is 0).

2 rules failed.

@github-actions
Copy link
Copy Markdown

Qwiet LogoQwiet Logo

Checking analysis of application shiftleft-python-demo against 3 build rules.

Using sl version 0.9.2509 (32315c47fd2cff75fe89e7cc80b6ac271119d689).

querying scans/check: API returned status 402, with code: 'SUBSCRIPTION_MAX_PROJECTS_EXCEEDED' message: 'You have now consumed all 5 apps that are allowed for your scan limit.'.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant