|
1 | 1 | { |
2 | 2 | "ignored_warnings": [ |
| 3 | + { |
| 4 | + "warning_type": "Command Injection", |
| 5 | + "warning_code": 14, |
| 6 | + "fingerprint": "0f98f6aeae590aca0d8eebf04dbd2dcaf4d1252822f138b4bcfe6e03455e5b4a", |
| 7 | + "check_name": "Execute", |
| 8 | + "message": "Possible command injection", |
| 9 | + "file": "app/jobs/backup_db_rds.rb", |
| 10 | + "line": 11, |
| 11 | + "link": "https://brakemanscanner.org/docs/warning_types/command_injection/", |
| 12 | + "code": "system(\"PGPASSWORD='#{ENV[\"DIAPER_DB_PASSWORD\"]}' pg_dump -Fc -v --host=#{ENV[\"DIAPER_DB_HOST\"]} --username=#{ENV[\"DIAPER_DB_USERNAME\"]} --dbname=#{ENV[\"DIAPER_DB_DATABASE\"]} -f #{\"#{Time.current.strftime(\"%Y%m%d%H%M%S\")}.rds.dump\"}\")", |
| 13 | + "render_path": null, |
| 14 | + "location": { |
| 15 | + "type": "method", |
| 16 | + "class": "BackupDbRds", |
| 17 | + "method": "run" |
| 18 | + }, |
| 19 | + "user_input": "ENV[\"DIAPER_DB_PASSWORD\"]", |
| 20 | + "confidence": "Medium", |
| 21 | + "cwe_id": [ |
| 22 | + 77 |
| 23 | + ], |
| 24 | + "note": "" |
| 25 | + }, |
3 | 26 | { |
4 | 27 | "warning_type": "Dynamic Render Path", |
5 | 28 | "warning_code": 15, |
6 | 29 | "fingerprint": "82ef033042422190ef49507207d51ed6ccd9593483630925baf0bf6c5e65033e", |
7 | 30 | "check_name": "Render", |
8 | 31 | "message": "Render path contains parameter value", |
9 | 32 | "file": "app/controllers/static_controller.rb", |
10 | | - "line": 25, |
| 33 | + "line": 20, |
11 | 34 | "link": "https://brakemanscanner.org/docs/warning_types/dynamic_render_path/", |
12 | 35 | "code": "render(template => \"static/#{params[:name]}\", {})", |
13 | 36 | "render_path": null, |
|
18 | 41 | }, |
19 | 42 | "user_input": "params[:name]", |
20 | 43 | "confidence": "Medium", |
| 44 | + "cwe_id": [ |
| 45 | + 22 |
| 46 | + ], |
21 | 47 | "note": "" |
22 | 48 | }, |
23 | 49 | { |
|
41 | 67 | "note": "" |
42 | 68 | } |
43 | 69 | ], |
44 | | - "updated": "2021-04-24 20:03:05 -0700", |
45 | | - "brakeman_version": "4.10.1" |
| 70 | + "updated": "2024-11-24 09:44:01 -0500", |
| 71 | + "brakeman_version": "6.2.1" |
46 | 72 | } |
0 commit comments