FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[Snyk] Security upgrade ubuntu from latest to 24.10 by tyleragypt · Pull Request #32 · tyleragypt/BenchmarkJava · GitHub

[Snyk] Security upgrade ubuntu from latest to 24.10 - #32

Open
tyleragypt wants to merge 1 commit into
masterfrom
snyk-fix-dfb2fb5ce5bf596486219408a96633f6
Open

tyleragypt wants to merge 1 commit into
masterfrom
snyk-fix-dfb2fb5ce5bf596486219408a96633f6

Conversation

Copy link
Copy Markdown
Owner

Snyk has created this PR to fix 4 vulnerabilities in the dockerfile dependencies of this project.

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Snyk changed the following file(s):

  • VMs/Dockerfile

We recommend upgrading to ubuntu:24.10, as this image has only 10 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
Directory Traversal
SNYK-UBUNTU2404-TAR-10769052
  371  
CVE-2025-5702
SNYK-UBUNTU2404-GLIBC-10321975
  300  
CVE-2025-5702
SNYK-UBUNTU2404-GLIBC-10321975
  300  
Insecure Storage of Sensitive Information
SNYK-UBUNTU2404-PAM-8303372
  300  
Improper Authentication
SNYK-UBUNTU2404-PAM-8352843
  300  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Directory Traversal
🦉 Improper Authentication

Copy link
Copy Markdown
Owner Author


Checkmarx One – Scan Summary & Details – 9d738f46-3a0e-4593-9b3d-2f47b70c47f2

New Issues (15)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
Missing User Instruction /Dockerfile: 2 detailsA user should be specified in the dockerfile, otherwise the image will run as root
ID: 3uNREHv%2BDDbvdgO3zXt2v%2B5TciA%3D
Apt Get Install Pin Version Not Defined /Dockerfile: 7 detailsWhen installing a package, its pin version should be defined
ID: JkVP8rPetYlX6YxrOci4%2Bd75zF8%3D
Apt Get Install Pin Version Not Defined /Dockerfile: 6 detailsWhen installing a package, its pin version should be defined
ID: VMYo0bqYbjN4MCx4TTXPSJkhrhs%3D
Apt Get Install Pin Version Not Defined /Dockerfile: 7 detailsWhen installing a package, its pin version should be defined
ID: QVUutnnOFcIgCoNlU%2FBBltWm8%2B8%3D
Apt Get Install Pin Version Not Defined /Dockerfile: 7 detailsWhen installing a package, its pin version should be defined
ID: J63MAcrbI6wSRXJP1eW7aYZUunc%3D
Apt Get Install Pin Version Not Defined /Dockerfile: 7 detailsWhen installing a package, its pin version should be defined
ID: 11OvNQPW5FvbtwrPtjJQ%2BbOafEA%3D
Apt Get Install Pin Version Not Defined /Dockerfile: 7 detailsWhen installing a package, its pin version should be defined
ID: wpNnxpX7%2B714wl%2BQ%2BdnbP6K7Qis%3D
Apt Get Install Pin Version Not Defined /Dockerfile: 7 detailsWhen installing a package, its pin version should be defined
ID: mThcugFZggodZOG4nQrrx31RwFA%3D
Use_of_Broken_or_Risky_Cryptographic_Algorithm /src/main/java/org/owasp/benchmark/helpers/Utils.java: 405 detailsIn getCipher, the application protects sensitive data using a cryptographic algorithm, getInstance, that is considered weak or even trivially broke...
ID: Kf4XPaqf9bn5RzfELiMfHgV4f1Q%3DAttack Vector
Healthcheck Instruction Missing /Dockerfile: 2 detailsEnsure that HEALTHCHECK is being used. The HEALTHCHECK instruction tells Docker how to test a container to check that it is still working
ID: I%2BUYhjKxMjo42aRgjlrygaia2ss%3D
MAINTAINER Instruction Being Used /Dockerfile: 3 detailsThe MAINTAINER instruction sets the Author field of the generated images. The LABEL instruction is a much more flexible version of this and you sh...
ID: 456EymRmcnJqFmWQSGUd9wHaMvU%3D
Multiple RUN, ADD, COPY, Instructions Listed /Dockerfile: 5 detailsMultiple commands (RUN, COPY, ADD) should be grouped in order to reduce the number of layers.
ID: Tcp0o8gmblEmZRQSK7XjQx0%2FJkA%3D
Unpinned Actions Full Length Commit SHA /codeql-analysis.yml: 47 detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
ID: UOcbYZcnH8edcJ9EIDBbQcxFZRU%3D
Unpinned Actions Full Length Commit SHA /codeql-analysis.yml: 35 detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
ID: ObVYxjWWBQFtn8BGykYTAK0WXQw%3D
Update Instruction Alone /Dockerfile: 7 detailsInstruction 'RUN update' should always be followed by ' install' in the same RUN statement
ID: pxOobdYB83zymgjypSvbYftva74%3D
Fixed Issues (997)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
CVE-2016-1000027 Maven-org.springframework:spring-webmvc-4.3.30.RELEASE
CVE-2016-1000027 Maven-org.springframework:spring-web-4.3.30.RELEASE
CVE-2016-1000031 Maven-commons-fileupload:commons-fileupload-1.3.3
CVE-2018-1000632 Maven-dom4j:dom4j-1.6.1
CVE-2019-0231 Maven-org.apache.mina:mina-core-2.0.0-RC1
CVE-2019-17571 Maven-log4j:log4j-1.2.17
CVE-2020-10683 Maven-dom4j:dom4j-1.6.1
CVE-2020-25638 Maven-org.hibernate:hibernate-core-3.6.10.Final
CVE-2021-4104 Maven-log4j:log4j-1.2.17
CVE-2022-22965 Maven-org.springframework:spring-beans-4.3.30.RELEASE
CVE-2022-23302 Maven-log4j:log4j-1.2.17
CVE-2022-23305 Maven-log4j:log4j-1.2.17
CVE-2022-23307 Maven-log4j:log4j-1.2.17
CVE-2022-23457 Maven-org.owasp.esapi:esapi-2.2.3.1
CVE-2022-24839 Maven-net.sourceforge.nekohtml:nekohtml-1.9.22
Client_DOM_Stored_XSS /src/main/webapp/js/testsuiteutils.js: 107
Client_DOM_Stored_XSS /src/main/webapp/js/testsuiteutils.js: 83
Client_DOM_Stored_XSS /src/main/webapp/js/testsuiteutils.js: 82
Client_DOM_Stored_XSS /src/main/webapp/js/testsuiteutils.js: 141
Client_DOM_Stored_XSS /src/main/webapp/js/testsuiteutils.js: 140
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest01182.java: 44
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest02058.java: 44
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest02610.java: 43
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00558.java: 45
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest02335.java: 45
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest01600.java: 43
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest01937.java: 45
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00494.java: 43
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00307.java: 44
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest01865.java: 59
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest01289.java: 43
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00741.java: 43
Command_Injection /src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00093.java: 59
Command_Injection /src/main/java/org/owasp/benchmark/helpers/SeparateClassRequest.java: 31
Cx78f40514-81ff Maven-org.apache.commons:commons-collections4-4.2
Cx78f40514-81ff Maven-commons-collections:commons-collections-3.2.2

More results are available on the CxOne platform

Policy Management Violations (1)

Policy Name: No highs or mediums
  • Rule Name: No Highs or Mediums
    Scanner: SAST

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL