Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,99 @@
{
"version": "2.1.0",
"runs": [
{
"invocations": [
{
"executionSuccessful": true,
"toolExecutionNotifications": [
{
"descriptor": {
"id": "Syntax error"
},
"level": "warning",
"message": {
"text": "Syntax error at line .github/workflows/sonarqube-hdf-emit.yml:234:\n When parsing a snippet as Bash for metavariable-pattern in rule 'yaml.github-actions.security.curl-eval.curl-eval', `{ steps.aws.outcome` was unexpected"
}
},
{
"descriptor": {
"id": "Syntax error"
},
"level": "warning",
"message": {
"text": "Syntax error at line .github/workflows/sonarqube-hdf-emit.yml:234:\n When parsing a snippet as Bash for metavariable-pattern in rule 'yaml.github-actions.security.gha-curl-pipe-shell.gha-curl-pipe-shell', `{ steps.aws.outcome` was unexpected"
}
}
]
}
],
"results": [
{
"fingerprints": {
"matchBasedId/v1": "requires login"
},
"locations": [
{
"physicalLocation": {
"artifactLocation": {
"uri": "tools/nist_catalog_to_inspec/generate.py",
"uriBaseId": "%SRCROOT%"
},
"region": {
"endColumn": 54,
"endLine": 168,
"snippet": {
"text": " with urllib.request.urlopen(ref, timeout=180) as resp: # noqa: S310"
},
"startColumn": 14,
"startLine": 168
}
}
}
],
"message": {
"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead."
},
"properties": {},
"ruleId": "python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected"
}
],
"tool": {
"driver": {
"name": "Semgrep OSS",
"rules": [
{
"defaultConfiguration": {
"level": "warning"
},
"fullDescription": {
"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead."
},
"help": {
"markdown": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\n#### \ud83d\udc8e Enable cross-file analysis and Pro rules for free at <a href='https://sg.run/pro'>sg.run/pro</a>\n\n<b>References:</b>\n - [Semgrep Rule](https://semgrep.dev/r/python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected)\n - [https://cwe.mitre.org/data/definitions/939.html](https://cwe.mitre.org/data/definitions/939.html)\n",
"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\ud83d\udc8e Enable cross-file analysis and Pro rules for free at sg.run/pro"
},
"helpUri": "https://semgrep.dev/r/python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected",
"id": "python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected",
"name": "python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected",
"properties": {
"precision": "very-high",
"tags": [
"CWE-939: Improper Authorization in Handler for Custom URL Scheme",
"LOW CONFIDENCE",
"OWASP-A01:2017 - Injection",
"security"
]
},
"shortDescription": {
"text": "Semgrep Finding: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected"
}
}
],
"semanticVersion": "1.174.0"
}
}
}
],
"$schema": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/os/schemas/sarif-schema-2.1.0.json"
}
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
{
"platform": {
"name": "Heimdall Tools",
"release": "2.6.29",
"release": "2.12.6",
"target_id": "Static Analysis Results Interchange Format"
},
"version": "2.6.29",
"version": "2.12.6",
"statistics": {},
"profiles": [
{
Expand All @@ -19,15 +19,14 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
],
"cwe": [
"CWE-120",
"CWE-20"
"CWE-20",
"CWE-120"
]
},
"refs": [],
Expand Down Expand Up @@ -56,8 +55,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -102,8 +100,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -138,8 +135,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -204,8 +200,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-000213"
],
"nist": [
"AC-3"
Expand Down Expand Up @@ -250,8 +245,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -311,8 +305,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -387,8 +380,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -423,15 +415,14 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
],
"cwe": [
"CWE-120",
"CWE-20"
"CWE-20",
"CWE-120"
]
},
"refs": [],
Expand Down Expand Up @@ -480,8 +471,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -516,8 +506,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -552,8 +541,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -588,8 +576,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -634,15 +621,14 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
],
"cwe": [
"CWE-120",
"CWE-20"
"CWE-20",
"CWE-120"
]
},
"refs": [],
Expand Down Expand Up @@ -671,15 +657,14 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
],
"cwe": [
"CWE-829",
"CWE-20"
"CWE-20",
"CWE-829"
]
},
"refs": [],
Expand All @@ -703,8 +688,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -755,8 +739,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -811,8 +794,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001090"
],
"nist": [
"SC-4"
Expand Down Expand Up @@ -847,8 +829,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -883,8 +864,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -919,8 +899,7 @@
{
"tags": {
"cci": [
"CCI-003173",
"CCI-001643"
"CCI-001310"
],
"nist": [
"SI-10"
Expand Down Expand Up @@ -953,7 +932,7 @@
]
}
],
"sha256": "c5ef8179c102a4ffdf896f4b07be4b8ec34b0c6f83037aa9372d390ab11be340"
"sha256": "c931b56079dbdad9c16c730972f6a0d380109fc1d180b073b7b026fb72975907"
}
],
"passthrough": {
Expand Down
Loading
Loading