Skip to content

Code Security Report: 12 total findings [main] #82

@mend-for-github-com

Description

@mend-for-github-com

Code Security Report

Scan Metadata

Latest Scan: 2025-03-06 05:31pm
Total Findings: 12 | New Findings: 0 | Resolved Findings: 0
Tested Project Files: 150
Detected Programming Languages: 2 (JavaScript / TypeScript*, Go)

  • Check this box to manually trigger a scan

Most Relevant Findings

The list below presents the 10 most relevant findings that need your attention. To view information on the remaining findings, navigate to the Mend Application.

SeverityVulnerability TypeCWEFileData FlowsDetected
MediumHeap Inspection

CWE-244

flags.go:69

12024-12-04 04:30pm
Vulnerable Code

COMMON_PASSWORD_SH string = "W"

Secure Code Warrior Training Material
 
MediumHeap Inspection

CWE-244

flags.go:78

12024-12-04 04:30pm
Vulnerable Code

APPLIANCE_PASSWORD_SH string = COMMON_PASSWORD_SH

Secure Code Warrior Training Material
 
MediumHeap Inspection

CWE-244

flags.go:91

12024-12-04 04:30pm
Vulnerable Code

BLADE_PASSWORD_SH string = COMMON_PASSWORD_SH

Secure Code Warrior Training Material
 
MediumHeap Inspection

CWE-244

flags.go:77

12024-12-04 04:30pm
Vulnerable Code

APPLIANCE_PASSWORD string = APPLIANCE + "-" + PASSWORD

Secure Code Warrior Training Material
 
MediumHeap Inspection

CWE-244

flags.go:161

12024-12-04 04:30pm
Vulnerable Code

HOST_PASSWORD_DFLT string = "admin12345"

Secure Code Warrior Training Material
 
MediumHeap Inspection

CWE-244

flags.go:34

12024-12-04 04:30pm
Vulnerable Code

PASSWORD string = "password"

Secure Code Warrior Training Material
 
MediumHeap Inspection

CWE-244

flags.go:154

12024-12-04 04:30pm
Vulnerable Code

BLADE_PASSWORD_DFLT string = "0penBmc"

Secure Code Warrior Training Material
 
MediumHeap Inspection

CWE-244

flags.go:104

12024-12-04 04:30pm
Vulnerable Code

HOST_PASSWORD_SH string = COMMON_PASSWORD_SH

Secure Code Warrior Training Material
 
MediumHeap Inspection

CWE-244

flags.go:147

12024-12-04 04:30pm
Vulnerable Code

APPLIANCE_PASSWORD_DFLT string = "dummypswd"

Secure Code Warrior Training Material
 
MediumWeak Pseudo-Random

CWE-338

sessions.go:192

12024-11-19 10:02pm
Vulnerable Code

r := rand.New(seed)

Secure Code Warrior Training Material

● Training

   ▪ Secure Code Warrior Weak Pseudo-Random Training

● Videos

   ▪ Secure Code Warrior Weak Pseudo-Random Video

● Further Reading

   ▪ OWASP Insecure Randomness

Findings Overview

Severity Vulnerability Type CWE Language Count
Medium Heap Inspection CWE-244 Go 11
Medium Weak Pseudo-Random CWE-338 Go 1

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions