You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The list below presents the 10 most relevant findings that need your attention. To view information on the remaining findings, navigate to the Mend Application.
Code Security Report
Scan Metadata
Latest Scan: 2024-05-27 12:19pm
Total Findings: 14 | New Findings: 0 | Resolved Findings: 0
Tested Project Files: 451
Detected Programming Languages: 1 (JavaScript / TypeScript*)
Most Relevant Findings
CWE-79
index.js:14
Vulnerable Code
bruno/packages/bruno-tests/src/echo/index.js
Lines 9 to 14 in 1c09e8a
1 Data Flow/s detected
bruno/packages/bruno-tests/src/echo/index.js
Line 13 in 1c09e8a
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Cross-Site Scripting Training
● Videos
▪ Secure Code Warrior Cross-Site Scripting Video
CWE-79
index.js:19
Vulnerable Code
bruno/packages/bruno-tests/src/echo/index.js
Lines 14 to 19 in 1c09e8a
1 Data Flow/s detected
bruno/packages/bruno-tests/src/echo/index.js
Line 17 in 1c09e8a
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Cross-Site Scripting Training
● Videos
▪ Secure Code Warrior Cross-Site Scripting Video
CWE-79
index.js:10
Vulnerable Code
bruno/packages/bruno-tests/src/echo/index.js
Lines 5 to 10 in 1c09e8a
1 Data Flow/s detected
bruno/packages/bruno-tests/src/echo/index.js
Line 8 in 1c09e8a
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Cross-Site Scripting Training
● Videos
▪ Secure Code Warrior Cross-Site Scripting Video
CWE-79
authorizationCode.js:86
Vulnerable Code
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Lines 81 to 86 in 1c09e8a
1 Data Flow/s detected
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Line 27 in 1c09e8a
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Line 28 in 1c09e8a
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Line 52 in 1c09e8a
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Line 61 in 1c09e8a
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Line 86 in 1c09e8a
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Cross-Site Scripting Training
● Videos
▪ Secure Code Warrior Cross-Site Scripting Video
CWE-1333
index.js:9
Vulnerable Code
bruno/packages/bruno-tests/src/index.js
Lines 4 to 9 in 1c09e8a
1 Data Flow/s detected
bruno/packages/bruno-tests/src/index.js
Line 9 in 1c09e8a
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Regex Denial of Service (ReDoS) Training
● Videos
▪ Secure Code Warrior Regex Denial of Service (ReDoS) Video
CWE-798
passwordCredentials.js:26
Vulnerable Code
bruno/packages/bruno-tests/src/auth/oauth2/passwordCredentials.js
Line 26 in 1c09e8a
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Hardcoded Password/Credentials Training
● Videos
▪ Secure Code Warrior Hardcoded Password/Credentials Video
● Further Reading
▪ OWASP Top Ten 2017 A3: Sensitive Data Exposure
▪ OWASP Top Ten Proactive Controls 2018 C8: Protect Data Everywhere
▪ OWASP Top Ten 2021 A02: Cryptographic Failures
CWE-117
clientCredentials.js:32
Vulnerable Code
bruno/packages/bruno-tests/src/auth/oauth2/clientCredentials.js
Lines 27 to 32 in 1c09e8a
1 Data Flow/s detected
bruno/packages/bruno-tests/src/auth/oauth2/clientCredentials.js
Line 18 in 1c09e8a
bruno/packages/bruno-tests/src/auth/oauth2/clientCredentials.js
Line 22 in 1c09e8a
bruno/packages/bruno-tests/src/auth/oauth2/clientCredentials.js
Line 32 in 1c09e8a
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Log Forging Training
● Videos
▪ Secure Code Warrior Log Forging Video
● Further Reading
▪ OWASP Log Forging
CWE-117
authorizationCode.js:105
Vulnerable Code
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Lines 100 to 105 in 1c09e8a
1 Data Flow/s detected
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Line 104 in 1c09e8a
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Log Forging Training
● Videos
▪ Secure Code Warrior Log Forging Video
● Further Reading
▪ OWASP Log Forging
CWE-117
authorizationCode.js:156
Vulnerable Code
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Lines 151 to 156 in 1c09e8a
1 Data Flow/s detected
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Line 154 in 1c09e8a
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Log Forging Training
● Videos
▪ Secure Code Warrior Log Forging Video
● Further Reading
▪ OWASP Log Forging
CWE-117
authorizationCode.js:29
Vulnerable Code
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Lines 24 to 29 in 1c09e8a
1 Data Flow/s detected
bruno/packages/bruno-tests/src/auth/oauth2/authorizationCode.js
Line 27 in 1c09e8a
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Log Forging Training
● Videos
▪ Secure Code Warrior Log Forging Video
● Further Reading
▪ OWASP Log Forging
Findings Overview
The text was updated successfully, but these errors were encountered: