You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The list below presents the 10 most relevant findings that need your attention. To view information on the remaining findings, navigate to the Mend Application.
Code Security Report
Scan Metadata
Latest Scan: 2024-11-04 04:59pm
Total Findings: 186 | New Findings: 0 | Resolved Findings: 0
Tested Project Files: 7339
Detected Programming Languages: 3 (JavaScript / TypeScript*, Go, Python)
Most Relevant Findings
CWE-732
fs.go:118
Vulnerable Code
grafana/pkg/plugins/storage/fs.go
Lines 113 to 118 in 446a5d4
1 Data Flow/s detected
grafana/pkg/plugins/storage/fs.go
Line 118 in 446a5d4
Secure Code Warrior Training Material
CWE-732
fs.go:105
Vulnerable Code
grafana/pkg/plugins/storage/fs.go
Lines 100 to 105 in 446a5d4
1 Data Flow/s detected
grafana/pkg/plugins/storage/fs.go
Line 105 in 446a5d4
Secure Code Warrior Training Material
CWE-732
file.go:130
Vulnerable Code
grafana/pkg/infra/log/file.go
Lines 125 to 130 in 446a5d4
1 Data Flow/s detected
grafana/pkg/infra/log/file.go
Line 130 in 446a5d4
Secure Code Warrior Training Material
CWE-79
index.tsx:41
Vulnerable Code
grafana/public/swagger/index.tsx
Lines 36 to 41 in 446a5d4
1 Data Flow/s detected
grafana/public/swagger/index.tsx
Line 41 in 446a5d4
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior DOM Based Cross-Site Scripting Training
● Videos
▪ Secure Code Warrior DOM Based Cross-Site Scripting Video
CWE-79
AppRootPage.tsx:91
Vulnerable Code
grafana/public/app/features/plugins/components/AppRootPage.tsx
Lines 86 to 91 in 446a5d4
1 Data Flow/s detected
grafana/public/app/features/plugins/components/AppRootPage.tsx
Line 96 in 446a5d4
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior DOM Based Cross-Site Scripting Training
● Videos
▪ Secure Code Warrior DOM Based Cross-Site Scripting Video
CWE-79
webhook-listener.go:160
Vulnerable Code
grafana/devenv/docker/ha-test-unified-alerting/webhook-listener.go
Lines 155 to 160 in 446a5d4
1 Data Flow/s detected
grafana/devenv/docker/ha-test-unified-alerting/webhook-listener.go
Line 131 in 446a5d4
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Cross-Site Scripting Training
● Videos
▪ Secure Code Warrior Cross-Site Scripting Video
CWE-79
webhook-listener.go:135
Vulnerable Code
grafana/devenv/docker/ha-test-unified-alerting/webhook-listener.go
Lines 130 to 135 in 446a5d4
1 Data Flow/s detected
grafana/devenv/docker/ha-test-unified-alerting/webhook-listener.go
Line 131 in 446a5d4
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Cross-Site Scripting Training
● Videos
▪ Secure Code Warrior Cross-Site Scripting Video
CWE-79
middleware.go:29
Vulnerable Code
grafana/pkg/tsdb/cloudwatch/routes/middleware.go
Lines 24 to 29 in 446a5d4
1 Data Flow/s detected
grafana/pkg/tsdb/cloudwatch/routes/middleware.go
Line 21 in 446a5d4
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Cross-Site Scripting Training
● Videos
▪ Secure Code Warrior Cross-Site Scripting Video
CWE-79
resource_handler.go:57
Vulnerable Code
grafana/pkg/tsdb/cloudwatch/resource_handler.go
Lines 52 to 57 in 446a5d4
1 Data Flow/s detected
grafana/pkg/tsdb/cloudwatch/resource_handler.go
Line 46 in 446a5d4
grafana/pkg/tsdb/cloudwatch/resource_handler.go
Line 51 in 446a5d4
grafana/pkg/tsdb/cloudwatch/resource_handler.go
Line 57 in 446a5d4
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Cross-Site Scripting Training
● Videos
▪ Secure Code Warrior Cross-Site Scripting Video
CWE-79
events_views.py:65
Vulnerable Code
grafana/devenv/docker/blocks/graphite09/files/events_views.py
Lines 60 to 65 in 446a5d4
1 Data Flow/s detected
grafana/devenv/docker/blocks/graphite09/files/events_views.py
Line 65 in 446a5d4
Secure Code Warrior Training Material
● Training
▪ Secure Code Warrior Cross-Site Scripting Training
● Videos
▪ Secure Code Warrior Cross-Site Scripting Video
Findings Overview
The text was updated successfully, but these errors were encountered: