Create Java application with intentional vulnerabilities and CodeQL autobuild workflow #2
6 new alerts including 1 critical severity security vulnerability
New alerts in code changed by this pull request
Security Alerts:
- 1 critical
- 3 high
- 1 medium
Other Alerts:
- 1 warning
See annotations below for details.
Annotations
Check failure on line 32 in src/main/java/com/example/database/UserDatabase.java
Code scanning / CodeQL
Query built by concatenation with a possibly-untrusted string High
Check failure on line 61 in src/main/java/com/example/database/UserDatabase.java
Code scanning / CodeQL
Query built by concatenation with a possibly-untrusted string High
Check failure on line 50 in src/main/java/com/example/security/CryptoUtils.java
Code scanning / CodeQL
Use of a potentially broken or risky cryptographic algorithm High
Check failure on line 81 in src/main/java/com/example/web/FileController.java
Code scanning / CodeQL
Building a command line with string concatenation Critical
Check warning on line 81 in src/main/java/com/example/web/FileController.java
Code scanning / CodeQL
Executing a command with a relative path Medium
Check warning on line 110 in src/main/java/com/example/web/FileController.java
Code scanning / CodeQL
Potential input resource leak Warning