Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update to blobfuse 2.3.0 release #247

Merged
merged 31 commits into from
Jul 2, 2024

Final cleanup of config and small helper function

cc74eb9
Select commit
Loading
Failed to load commit list.
Merged

Update to blobfuse 2.3.0 release #247

Final cleanup of config and small helper function
cc74eb9
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Code Security Check succeeded Jul 2, 2024 in 1m 17s

Code Security Report

New findings (7)

The Code Security Check detected a total of 7 new findings.

SeverityVulnerability TypeCWEFileData FlowsDate
MediumHeap Inspection

CWE-244

config.go:153

12024-06-11 04:43pm
Vulnerable Code

ClientSecret string `config:"clientsecret" yaml:"clientsecret,omitempty"`

Secure Code Warrior Training Material
 
MediumHeap Inspection

CWE-244

azauth.go:56

12024-06-11 04:43pm
Vulnerable Code

ClientSecret string

Secure Code Warrior Training Material
 
LowWeak Hash Strength

CWE-916

utils.go:557

12024-06-11 04:43pm
Vulnerable Code

hasher := md5.New()

Secure Code Warrior Training Material

● Training

   ▪ Secure Code Warrior Weak Hash Strength Training

● Videos

   ▪ Secure Code Warrior Weak Hash Strength Video

● Further Reading

   ▪ OWASP Cryptographic Storage Cheat Sheet

   ▪ OWASP Transport Layer Protection Cheat Sheet

   ▪ OWASP Password Storage Cheat Sheet

   ▪ OWASP Using a broken or risky cryptographic algorithm article

 
LowWeak Hash Strength

CWE-916

block_blob.go:719

12024-06-11 04:43pm
Vulnerable Code

return errors.New("md5 sum mismatch on download")

Secure Code Warrior Training Material

● Training

   ▪ Secure Code Warrior Weak Hash Strength Training

● Videos

   ▪ Secure Code Warrior Weak Hash Strength Video

● Further Reading

   ▪ OWASP Cryptographic Storage Cheat Sheet

   ▪ OWASP Transport Layer Protection Cheat Sheet

   ▪ OWASP Password Storage Cheat Sheet

   ▪ OWASP Using a broken or risky cryptographic algorithm article

 
LowWeak Hash Strength

CWE-916

block_blob.go:703

12024-06-11 04:43pm
Vulnerable Code

log.Warn("BlockBlob::ReadToFile : Failed to generate MD5 Sum for %s", name)

Secure Code Warrior Training Material

● Training

   ▪ Secure Code Warrior Weak Hash Strength Training

● Videos

   ▪ Secure Code Warrior Weak Hash Strength Video

● Further Reading

   ▪ OWASP Cryptographic Storage Cheat Sheet

   ▪ OWASP Transport Layer Protection Cheat Sheet

   ▪ OWASP Password Storage Cheat Sheet

   ▪ OWASP Using a broken or risky cryptographic algorithm article

 
LowWeak Hash Strength

CWE-916

block_blob.go:718

12024-06-11 04:43pm
Vulnerable Code

log.Err("BlockBlob::ReadToFile : MD5 Sum mismatch %s", name)

Secure Code Warrior Training Material

● Training

   ▪ Secure Code Warrior Weak Hash Strength Training

● Videos

   ▪ Secure Code Warrior Weak Hash Strength Video

● Further Reading

   ▪ OWASP Cryptographic Storage Cheat Sheet

   ▪ OWASP Transport Layer Protection Cheat Sheet

   ▪ OWASP Password Storage Cheat Sheet

   ▪ OWASP Using a broken or risky cryptographic algorithm article

 
LowWeak Hash Strength

CWE-916

block_blob.go:714

12024-06-11 04:43pm
Vulnerable Code

log.Warn("BlockBlob::ReadToFile : Failed to get MD5 Sum for blob %s", name)

Secure Code Warrior Training Material

● Training

   ▪ Secure Code Warrior Weak Hash Strength Training

● Videos

   ▪ Secure Code Warrior Weak Hash Strength Video

● Further Reading

   ▪ OWASP Cryptographic Storage Cheat Sheet

   ▪ OWASP Transport Layer Protection Cheat Sheet

   ▪ OWASP Password Storage Cheat Sheet

   ▪ OWASP Using a broken or risky cryptographic algorithm article

Resolved findings (2)

With your last commit you resolved 2 findings.

SeverityVulnerability TypeCWEFileData FlowsDate
MediumHeap Inspection

CWE-244

config.go:148

12024-04-02 02:23pm
MediumHeap Inspection

CWE-244

azauth.go:54

12024-04-02 02:23pm

Overall findings

The Code Security Check detected a total of 29 findings, 15 of them high severity. More details about the overall state can be found in the Mend Application.


Scan token: 44706ab997144180a7bd1f5dd867626e