Skip to content

Create laravel.yml #350

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Create laravel.yml #350

wants to merge 1 commit into from

Conversation

Hosampor
Copy link

No description provided.

@sstephanou-bc
Copy link

Logo
Checkmarx One – Scan Summary & Details94f8f73f-8a50-4eda-92fb-6e809e2ec956

New Issues (11)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2021-0341 Maven-com.squareup.okhttp3:okhttp-3.14.7
detailsRecommended version: 4.9.2
Description: In "verifyHostName" method of "OkHostnameVerifier.java", there is a possible way to accept a certificate for the wrong domain due to improperly use...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
HIGH CVE-2021-0341 Maven-com.squareup.okhttp3:okhttp-4.2.2
detailsRecommended version: 4.9.2
Description: In "verifyHostName" method of "OkHostnameVerifier.java", there is a possible way to accept a certificate for the wrong domain due to improperly use...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
HIGH CVE-2023-2976 Maven-com.google.guava:guava-20.0
detailsRecommended version: 32.0.0.jre-redhat-00001
Description: Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 through 31.1-jre on Unix syste...
Attack Vector: LOCAL
Attack Complexity: LOW
Vulnerable Package
HIGH CVE-2024-45338 Go-golang.org/x/net-v0.0.0-20190108225652-1e06a53dbb7e
detailsRecommended version: v0.25.1-0.20250304182835-b70a9e3eaa27
Description: An attacker can craft an input to the "Parse" function, that will be processed non-linearly with respect to its length, resulting in extremely slow...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
HIGH Cxdfe95b9f-ea87 Maven-org.jetbrains.kotlin:kotlin-compiler-embeddable-1.3.61
detailsRecommended version: 1.7.0
Description: Kotlin is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability ...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
MEDIUM CVE-2018-10237 Maven-com.google.guava:guava-20.0
detailsRecommended version: 32.0.0.jre-redhat-00001
Description: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against se...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
MEDIUM CVE-2019-11404 Maven-io.arrow-kt:arrow-core-0.7.1
detailsRecommended version: 0.10.0
Description: arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of thes...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
MEDIUM CVE-2020-29582 Maven-org.jetbrains.kotlin:kotlin-scripting-jvm-1.3.61
detailsRecommended version: 1.4.21
Description: In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from su...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
MEDIUM CVE-2020-29582 Maven-org.jetbrains.kotlin:kotlin-compiler-embeddable-1.3.61
detailsRecommended version: 1.7.0
Description: In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from su...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
MEDIUM CVE-2022-24329 Maven-org.jetbrains.kotlin:kotlin-stdlib-1.3.61
detailsRecommended version: 1.6.0
Description: In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
LOW CVE-2020-8908 Maven-com.google.guava:guava-20.0
detailsRecommended version: 32.0.0.jre-redhat-00001
Description: A temp directory creation vulnerability exist in Guava versions prior to 30.0 allowing an attacker with access to the machine to potentially access...
Attack Vector: LOCAL
Attack Complexity: LOW
Vulnerable Package
Fixed Issues (1447)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 743
HIGH Array Without Maximum Number of Items (v3) /specification.yaml: 235
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 482
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1431
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 545
HIGH Array Without Maximum Number of Items (v3) /specification.yaml: 323
HIGH Array Without Maximum Number of Items (v3) /specification.yaml: 399
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 577
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 545
HIGH Array Without Maximum Number of Items (v3) /specification.yaml: 437
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1133
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 100
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 141
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 313
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 521
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1273
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 254
HIGH Array Without Maximum Number of Items (v3) /specification.yaml: 417
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 428
HIGH Array Without Maximum Number of Items (v3) /specification.yaml: 1040
HIGH Array Without Maximum Number of Items (v3) /specification.yaml: 96
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1435
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 428
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1120
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 974
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 100
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 577
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 63
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 750
HIGH Array Without Maximum Number of Items (v3) /specification.yaml: 807
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1120
HIGH Array Without Maximum Number of Items (v3) /specification.yaml: 358
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 313
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 482
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1129
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1435
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1113
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1113
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 917
HIGH Array Without Maximum Number of Items (v3) /specification.yaml: 929
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1273
HIGH Array Without Maximum Number of Items (v3) /specification.yaml: 1036
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 521
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 1431
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 322
HIGH Array Without Maximum Number of Items (v3) /openapi.yaml: 344
HIGH CVE-2024-45296 Npm-path-to-regexp-1.8.0
HIGH Cx89601373-08db Npm-debug-3.2.7
HIGH Cx89601373-08db Npm-debug-3.1.0
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 130
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 107
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 58
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 87
HIGH Security Field On Operations Has An Empty Object Definition (v3) /specification.yaml: 107
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 29
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 58
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 68
HIGH Security Field On Operations Has An Empty Object Definition (v3) /specification.yaml: 88
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 105
HIGH Security Field On Operations Has An Empty Object Definition (v3) /specification.yaml: 150
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 130
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 130
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 179
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 52
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 151
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 151
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 105
HIGH Security Field On Operations Has An Empty Object Definition (v3) /specification.yaml: 68
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 87
HIGH Security Field On Operations Has An Empty Object Definition (v3) /specification.yaml: 129
HIGH Security Field On Operations Has An Empty Object Definition (v3) /specification.yaml: 48
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 91
HIGH Security Field On Operations Has An Empty Object Definition (v3) /openapi.yaml: 179
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1205
MEDIUM Additional Properties Too Permissive /specification.yaml: 897
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1124
MEDIUM Additional Properties Too Permissive /openapi.yaml: 972
MEDIUM Additional Properties Too Permissive /openapi.yaml: 651
MEDIUM Additional Properties Too Permissive /openapi.yaml: 710
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1165
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1246
MEDIUM Additional Properties Too Permissive /specification.yaml: 909
MEDIUM Additional Properties Too Permissive /specification.yaml: 691
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1387
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1408
MEDIUM Additional Properties Too Permissive /openapi.yaml: 932
MEDIUM Additional Properties Too Permissive /openapi.yaml: 875
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1124
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1246
MEDIUM Additional Properties Too Permissive /specification.yaml: 1031
MEDIUM Additional Properties Too Permissive /openapi.yaml: 915
MEDIUM Additional Properties Too Permissive /openapi.yaml: 811
MEDIUM Additional Properties Too Permissive /openapi.yaml: 795
MEDIUM Additional Properties Too Permissive /openapi.yaml: 934
MEDIUM Additional Properties Too Permissive /specification.yaml: 1014
MEDIUM Additional Properties Too Permissive /openapi.yaml: 992
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1080
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1408
MEDIUM Additional Properties Too Permissive /specification.yaml: 812
MEDIUM Additional Properties Too Permissive /specification.yaml: 869
MEDIUM Additional Properties Too Permissive /openapi.yaml: 862
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1278
MEDIUM Additional Properties Too Permissive /openapi.yaml: 901
MEDIUM Additional Properties Too Permissive /openapi.yaml: 759
MEDIUM Additional Properties Too Permissive /specification.yaml: 546
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1106
MEDIUM Additional Properties Too Permissive /openapi.yaml: 932
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1231
MEDIUM Additional Properties Too Permissive /openapi.yaml: 583
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1231
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1278
MEDIUM Additional Properties Too Permissive /specification.yaml: 728
MEDIUM Additional Properties Too Permissive /openapi.yaml: 979
MEDIUM Additional Properties Too Permissive /specification.yaml: 881
MEDIUM Additional Properties Too Permissive /specification.yaml: 784
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1205
MEDIUM Additional Properties Too Permissive /openapi.yaml: 811
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1188
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1387
MEDIUM Additional Properties Too Permissive /openapi.yaml: 992
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1080
MEDIUM Additional Properties Too Permissive /openapi.yaml: 759
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1088
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1188
MEDIUM Additional Properties Too Permissive /specification.yaml: 934
MEDIUM Additional Properties Too Permissive /openapi.yaml: 754
MEDIUM Additional Properties Too Permissive /openapi.yaml: 840
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1271
MEDIUM Additional Properties Too Permissive /openapi.yaml: 823
MEDIUM Additional Properties Too Permissive /specification.yaml: 583
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1165
MEDIUM Additional Properties Too Permissive /specification.yaml: 845
MEDIUM Additional Properties Too Permissive /openapi.yaml: 1271
MEDIUM Additional Properties Too Permissive /specification.yaml: 926
MEDIUM Default Response Undefined On Operations (v3) /specification.yaml: 73
MEDIUM Default Response Undefined On Operations (v3) /specification.yaml: 91
MEDIUM Default Response Undefined On Operations (v3) /openapi.yaml: 253

More results are available on the CxOne platform

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants