snappy-java icon indicating copy to clipboard operation
snappy-java copied to clipboard

Veracode Security Vulnerabilities

Open jcascante opened this issue 5 years ago • 0 comments

When we run the snappy-java Veracode Scan, we can see the following vulnerabilities...

snappy-java-1.1.7.7.jar

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE ID 78)(1 flaw) snappy-java-1.1.7.7.jar. org/.../xerial/snappy/OSInfo.java 178

  • Untrusted Search Path(2 flaws) snappy-java-1.1.7.7.jar. org/.../snappy/SnappyLoader.java 198 10/17/20 snappy-java-1.1.7.7.jar. org/.../snappy/SnappyLoader.java 201 10/17/20

  • Directory Traversal(9 flaws)

jcascante avatar Oct 08 '20 00:10 jcascante