-
Bug
-
Resolution: Not Done
-
Highest
-
Istanbul Release
Sonarcloud identified the following security bugs in your project and, as agreed by the TSC, should be fixed within the Istanbul release. Any not finished in Istanbul must be fixed within the Jakarta release. Follow each of the URLs for details on each each bug, along with recommended fixes.
The verification URL for these issues will be <https://sonarcloud.io/organizations/onap/issues?resolved=false&sonarsourceSecurity=command-injection&projects=onap_vfc-nfvo-driver-vnfm-gvnfm-juju>.
If any of the links below fail, please find your code on the master list found at <https://sonarcloud.io/organizations/onap/issues?resolved=false&sonarsourceSecurity=command-injection>.
Project: onap_vfc-nfvo-driver-vnfm-gvnfm-juju
Component: onap_vfc-nfvo-driver-vnfm-gvnfm-juju:Juju-vnfmadapterService/service/src/main/java/org/onap/vfc/nfvo/vnfm/gvnfm/jujuvnfmadapter/common/EntityUtils.java
Message: Refactor this code to not construct the OS command from tainted, user-controlled data.
Severity: BLOCKER
Line: 212
Effort: 30min
Creation-Date: 2017-07-04T11:30:27+0200
URL: https://sonarcloud.io/project/issues?id=onap_vfc-nfvo-driver-vnfm-gvnfm-juju&issues=AW8WGWCstsS0rVJwJlrS&open=AW8WGWCstsS0rVJwJlrS
- clones
-
APPC-1917 fix CRITICAL weak-cryptography issues identified in sonarcloud
- Closed
- is cloned by
-
PORTAL-1070 fix CRITICAL sql-injection issues identified in sonarcloud
- Closed
-
SDC-3607 fix CRITICAL xss (cross site scripting) issues identified in sonarcloud
- Closed
- relates to
-
REQ-443 CONTINUATION OF BEST PRACTICES BADGING SCORE IMPROVEMENTS FOR SILVER LEVEL
- In Progress