Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update to fix vuln #18

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open

Update to fix vuln #18

wants to merge 1 commit into from

Conversation

IAmATeaPot418
Copy link
Collaborator

@IAmATeaPot418 IAmATeaPot418 commented Apr 6, 2023

Endor Labs detected 2 policy violations associated with this pull request.

Please review all findings to address these issues.

  • hello wor
  • hello world
  • hello worlllld
🚩 Policy Violation: Critical or High Reachable Vulnerabilities

Package: com.endor.webapp:[email protected]

Dependency: com.endor.example:[email protected]

🚫 GHSA-mjmj-j48q-9wg2: SnakeYaml Constructor Deserialization Remote Code Execution
  • Severity: Critical
  • Tags: Transitive Dependency Test Dependency Reachable Function Reachable Dependency
  • Summary: org.hsqldb:[email protected] has a critical vulnerability identified by GHSA-77xx-rxvh-q682: HyperSQL DataBase vulnerable to remote code execution when processing untrusted input. A vulnerable function is potentially reachable. This vulnerability was fixed in version 2.7.1 org.hsqldb:[email protected] is a direct dependency of org.owasp:[email protected].
  • Remediation: Update org.owasp:[email protected] to use org.hsqldb:hsqldb version 2.7.1 (current: 2.3.6, latest: 2.7.1).
🚫 GHSA-mjmj-j48q-9wg2: SnakeYaml Constructor Deserialization Remote Code Execution
  • Tags: Transitive Dependency Test Dependency Reachable Function Reachable Dependency
  • Summary: org.hsqldb:[email protected] has a critical vulnerability identified by GHSA-77xx-rxvh-q682: HyperSQL DataBase vulnerable to remote code execution when processing untrusted input. A vulnerable function is potentially reachable. This vulnerability was fixed in version 2.7.1 org.hsqldb:[email protected] is a direct dependency of org.owasp:[email protected].
  • Remediation: Update org.owasp:[email protected] to use org.hsqldb:hsqldb version 2.7.1 (current: 2.3.6, latest: 2.7.1).

Dependency: com.endor.example:[email protected]

🚫 GHSA-mjmj-j48q-9wg2: SnakeYaml Constructor Deserialization Remote Code Execution - **Tags**: `Transitive Dependency` `Test Dependency` `Reachable Function` `Reachable Dependency` - **Summary**: org.hsqldb:[email protected] has a critical vulnerability identified by GHSA-77xx-rxvh-q682: HyperSQL DataBase vulnerable to remote code execution when processing untrusted input. A vulnerable function is potentially reachable. This vulnerability was fixed in version 2.7.1 org.hsqldb:[email protected] is a direct dependency of org.owasp:[email protected]. - **Remediation**: Update org.owasp:[email protected] to use org.hsqldb:hsqldb version 2.7.1 (current: 2.3.6, latest: 2.7.1).
🚫 GHSA-mjmj-j48q-9wg2: SnakeYaml Constructor Deserialization Remote Code Execution
  • Tags: Transitive Dependency Test Dependency Reachable Function Reachable Dependency
  • Summary: org.hsqldb:[email protected] has a critical vulnerability identified by GHSA-77xx-rxvh-q682: HyperSQL DataBase vulnerable to remote code execution when processing untrusted input. A vulnerable function is potentially reachable. This vulnerability was fixed in version 2.7.1 org.hsqldb:[email protected] is a direct dependency of org.owasp:[email protected].
  • Remediation: Update org.owasp:[email protected] to use org.hsqldb:hsqldb version 2.7.1 (current: 2.3.6, latest: 2.7.1).
🚫 GHSA-x873-6rgc-94jc: Spring Security logout not clearing security context input - Summary: org.hsqldb:[email protected] has a critical vulnerability identified by GHSA-77xx-rxvh-q682: HyperSQL DataBase vulnerable to remote code execution when processing untrusted input. A vulnerable function is potentially reachable. This vulnerability was fixed in version 2.7.1 org.hsqldb:[email protected] is a direct dependency of org.owasp:[email protected]. - Remediation: Update org.owasp:[email protected] to use org.hsqldb:hsqldb version 2.7.1 (current: 2.3.6, latest: 2.7.1).
⚠️ Policy Warning: License Compliance Violation for Dependency ch.qos.logback:[email protected]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant