Txmv2 with dual transmission #15459
Txmv2 with dual transmission #15459
24 new alerts including 4 critical severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 4 critical
- 15 high
- 5 medium
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Check failure on line 2 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check warning on line 25 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Missing origin verification in `postMessage` handler Medium
Check failure on line 25 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 25 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Remote property injection High
.
Check failure on line 43 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 97 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Missing regular expression anchor High
Check failure on line 98 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Missing regular expression anchor High
Check failure on line 115 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 120 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 157 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 164 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 164 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Missing regular expression anchor High
Check failure on line 164 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Missing regular expression anchor High
Check failure on line 164 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Missing regular expression anchor High
Check warning on line 164 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Prototype-polluting assignment Medium
.
Check warning on line 164 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Prototype-polluting assignment Medium
.
Check warning on line 164 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Missing origin verification in `postMessage` handler Medium
Check failure on line 174 in core/web/assets/main.ec7b7e88c8c965c1e482.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 110 in core/internal/cltest/cltest.go
Code scanning / CodeQL
Hard-coded credentials Critical
.
Check failure on line 321 in core/internal/cltest/mocks.go
Code scanning / CodeQL
Hard-coded credentials Critical
.
Check failure on line 377 in core/internal/cltest/mocks.go
Code scanning / CodeQL
Hard-coded credentials Critical
.
Check failure on line 232 in core/services/ocr2/plugins/ccip/testhelpers/integration/jobspec.go
Code scanning / CodeQL
Potentially unsafe quoting Critical test
contains a double quote, it could break out of the enclosing quotes.Code scanning / CodeQL
Reflected cross-site scripting Medium test
.
Check failure on line 239 in core/sessions/localauth/orm.go
Code scanning / CodeQL
Use of insufficient randomness as the key of a cryptographic algorithm High
generated with a cryptographically weak RNG.