Implement DevSecOps GHAS Demo Features with Intentional Vulnerabilities #83
9 new alerts including 3 high severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 3 high
Other Alerts:
- 6 notes
See annotations below for details.
Annotations
Check notice on line 107 in src/webapp01/Pages/DevSecOps2.cshtml.cs
Code scanning / CodeQL
Generic catch clause Note
Check notice on line 115 in src/webapp01/Pages/DevSecOps2.cshtml.cs
Code scanning / CodeQL
Inefficient use of ContainsKey Note
Check notice on line 116 in src/webapp01/Pages/DevSecOps2.cshtml.cs
Code scanning / CodeQL
Call to System.IO.Path.Combine Note
Check failure on line 118 in src/webapp01/Pages/DevSecOps2.cshtml.cs
Code scanning / CodeQL
Log entries created from user input High
Check failure on line 122 in src/webapp01/Pages/DevSecOps2.cshtml.cs
Code scanning / CodeQL
Log entries created from user input High
Check notice on line 128 in src/webapp01/Pages/DevSecOps2.cshtml.cs
Code scanning / CodeQL
Generic catch clause Note
Check notice on line 159 in src/webapp01/Pages/DevSecOps2.cshtml.cs
Code scanning / CodeQL
Generic catch clause Note
Check failure on line 189 in src/webapp01/Pages/DevSecOps2.cshtml.cs
Code scanning / CodeQL
Clear text storage of sensitive information High
Check notice on line 210 in src/webapp01/Pages/DevSecOps2.cshtml.cs
Code scanning / CodeQL
Generic catch clause Note