-
Epic
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
None
-
None
-
cnv-sast-tracker
-
False
-
-
False
-
To Do
-
33% To Do, 0% In Progress, 67% Done
-
---
-
---
Triggered by CNV-29396, every CNV release has to be checked for new SAST issues, and the progress of already discovered SAST issues has to be checked.
SAST issues are listed in https://app.snyk.io/org/red-hat-openshift-virtualisation/reporting?v=1&context[page]=issues-detail&issue_status=%255B%2522Open%2522%255D&issue_by=Severity&table_issues_detail_cols=SCORE%257CCVE%257CCWE%257CPROJECT%257CEXPLOIT%2520MATURITY%257CAUTO%2520FIXABLE%257CINTRODUCED%257CSNYK%2520PRODUCT&product_name=%255B%2522Snyk%2520Code%2522%255D&issue_severity=%255B%2522Critical%2522%252C%2522High%2522%255D
Every CNV version should have a blocking bug reported, which has to be closed manually by a human to confirm that the report is checked for the given CNV version.
- relates to
-
CNV-36208 [CWE-79] main - containerized-data-importer - pkg/uploadproxy/uploadproxy.go - Cross-site Scripting (XSS)
- Closed
-
CNV-36209 [CWE-79] release-v1.55 - containerized-data-importer - pkg/uploadproxy/uploadproxy.go - Cross-site Scripting (XSS)
- Closed
-
CNV-36210 [CWE-79] release-v1.57 - containerized-data-importer - pkg/uploadproxy/uploadproxy.go - Cross-site Scripting (XSS)
- Closed
-
CNV-36211 [CWE-79] release-v1.56 - containerized-data-importer - pkg/uploadproxy/uploadproxy.go - Cross-site Scripting (XSS)
- Closed