Skip to content

Conversation

@gacevedo
Copy link

@gacevedo gacevedo commented Jun 24, 2024

Qwiet.AI AutoFix

This PR was created automatically by the Qwiet.AI autofix tool.
As long as it is open, subsequent scans and generated fixes to this same branch
will be added to it as new commits.

Each commit fixes one vulnerability.

Some manual intervention might be required before merging this PR.

Fixes

  • AutoPatch applied to src/main/java/io/shiftleft/controller/AccountController.java for finding 96 (Sensitive Data Leak: Sensitive Data is Leaked to Log in AccountController.depositIntoAccount) of project shiftleft-java-wavecoder-autopatch

  • AutoPatch applied to src/main/java/io/shiftleft/controller/AccountController.java for finding 94 (Sensitive Data Leak: Sensitive Data is Leaked to Log in AccountController.addInterestToAccount) of project shiftleft-java-wavecoder-autopatch

  • AutoPatch applied to src/main/java/io/shiftleft/controller/SearchController.java for finding 98 (Remote Code Execution: Code Injection Through Attacker-controlled Data via foo in SearchController.doGetSearch) of project shiftleft-java-wavecoder-autopatch

  • AutoPatch applied to src/main/java/io/shiftleft/controller/CustomerController.java for finding 97 (Sensitive Data Leak: Security-sensitive Data Leaked to Console via firstName in CustomerController.debugEscaped) of project shiftleft-java-wavecoder-autopatch

  • AutoPatch applied to src/main/java/io/shiftleft/controller/AccountController.java for finding 93 (Sensitive Data Leak: Sensitive Data is Leaked to Log in AccountController.withdrawFromAccount) of project shiftleft-java-wavecoder-autopatch

  • AutoPatch applied to src/main/java/io/shiftleft/model/Account.java for finding 92 (Sensitive Data Leak: Sensitive Data is Leaked via routingNumber to Log in Account.<init>) of project shiftleft-java-wavecoder-autopatch

  • AutoPatch applied to src/main/java/io/shiftleft/controller/PatientController.java for finding 91 (Sensitive Data Leak: Sensitive Data is Leaked to Log in PatientController.getPatient) of project shiftleft-java-wavecoder-autopatch

  • AutoPatch applied to src/main/java/io/shiftleft/controller/AdminController.java for finding 85 (Deserialization: Attacker-controlled Data Used in Unsafe Deserialization Function via auth in AdminController.doPostLogin) of project shiftleft-java-wavecoder-autopatch

  • AutoPatch applied to src/main/java/io/shiftleft/controller/CustomerController.java for finding 83 (Cross-Site Scripting: Attacker-Controlled Data Used as HTML Content via lastName in CustomerController.debug) of project shiftleft-java-wavecoder-autopatch

  • AutoPatch applied to src/main/java/io/shiftleft/controller/CustomerController.java for finding 82 (Cross-Site Scripting: Attacker-Controlled Data Used as HTML Content via tin in CustomerController.debug) of project shiftleft-java-wavecoder-autopatch

@gacevedo gacevedo closed this Jul 9, 2024
@gacevedo gacevedo deleted the qwietai/autofix/fix0001 branch July 9, 2024 18:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant