Skip to content

Conversation

@marob
Copy link
Contributor

@marob marob commented Jan 29, 2026

No description provided.

@marob marob added this to the IT 165 milestone Jan 29, 2026
@vitam-prg
Copy link
Collaborator

Logo
Checkmarx One – Scan Summary & Details0b93950f-8246-4e4e-a707-a7a6b541d1e9

New Issues (5)

Checkmarx found the following issues in this Pull Request

# Severity Issue Source File / Package Checkmarx Insight
1 MEDIUM Parameter_Tampering /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/discussion/rest/DiscussionController.java: 45
detailsMethod addMessage at line 45 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/discussion/rest/DiscussionController.java gets user inp...
Attack Vector
2 MEDIUM Parameter_Tampering /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/discussion/rest/DiscussionController.java: 40
detailsMethod createDiscussion at line 40 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/discussion/rest/DiscussionController.java gets us...
Attack Vector
3 MEDIUM Parameter_Tampering /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/discussion/rest/DiscussionController.java: 45
detailsMethod addMessage at line 45 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/discussion/rest/DiscussionController.java gets user inp...
Attack Vector
4 MEDIUM Parameter_Tampering /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/discussion/rest/DiscussionController.java: 50
detailsMethod resolveDiscussion at line 50 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/discussion/rest/DiscussionController.java gets u...
Attack Vector
5 MEDIUM Parameter_Tampering /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/discussion/rest/DiscussionController.java: 55
detailsMethod unresolveDiscussion at line 55 of /api/api-iam/iam/src/main/java/fr/gouv/vitamui/iam/server/discussion/rest/DiscussionController.java gets...
Attack Vector
Fixed Issues (15)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
HIGH CVE-2022-40152 Maven-com.fasterxml.woodstox:woodstox-core-6.2.6
MEDIUM CVE-2023-44483 Maven-org.apache.santuario:xmlsec-2.3.0
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 80
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 106
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 65
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 80
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 105
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 105
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 106
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 80
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 80
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 81
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 105
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 106
LOW Log_Forging /api/api-referential/referential/src/main/java/fr/gouv/vitamui/referential/server/rest/LogbookManagementOperationController.java: 65

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants