Skip to content

Commit 9120504

Browse files
authored
fix: Add expected vulnerabilities to tests (#278)
1 parent 5178a5d commit 9120504

3 files changed

Lines changed: 10 additions & 10 deletions

File tree

docs/multiple-tests/all-patterns/results.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,13 +30,13 @@
3030
<error
3131
source="vulnerability_medium"
3232
line="1"
33-
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34480: Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/ma ...) (update to 2.25.4)"
33+
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34480: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging) (update to 2.25.4)"
3434
severity="warning"
3535
/>
3636
<error
3737
source="vulnerability_medium"
3838
line="1"
39-
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration) (update to 2.25.4)"
39+
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification) (update to 2.25.4)"
4040
severity="warning"
4141
/>
4242
<error

docs/multiple-tests/pattern-vulnerability-critical/results.xml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -43,13 +43,13 @@
4343
<error
4444
source="vulnerability_critical"
4545
line="14"
46-
message="Insecure dependency npm/axios@0.21.0 (CVE-2025-62718: axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization) (update to 1.15.0)"
46+
message="Insecure dependency npm/axios@0.21.0 (CVE-2025-62718: axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization) (update to 0.31.0)"
4747
severity="error"
4848
/>
4949
<error
5050
source="vulnerability_critical"
5151
line="14"
52-
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-40175: Axios is a promise based HTTP client for the browser and Node.js. Prio ...) (update to 1.15.0)"
52+
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-40175: axios: Axios: Remote Code Execution via Prototype Pollution escalation) (update to 0.31.0)"
5353
severity="error"
5454
/>
5555
</file>
@@ -58,13 +58,13 @@
5858
<error
5959
source="vulnerability_critical"
6060
line="5"
61-
message="Insecure dependency npm/axios@0.21.0 (CVE-2025-62718: axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization) (update to 1.15.0)"
61+
message="Insecure dependency npm/axios@0.21.0 (CVE-2025-62718: axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization) (update to 0.31.0)"
6262
severity="error"
6363
/>
6464
<error
6565
source="vulnerability_critical"
6666
line="5"
67-
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-40175: Axios is a promise based HTTP client for the browser and Node.js. Prio ...) (update to 1.15.0)"
67+
message="Insecure dependency npm/axios@0.21.0 (CVE-2026-40175: axios: Axios: Remote Code Execution via Prototype Pollution escalation) (update to 0.31.0)"
6868
severity="error"
6969
/>
7070
</file>

docs/multiple-tests/pattern-vulnerability-medium/results.xml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -242,13 +242,13 @@
242242
<error
243243
source="vulnerability_medium"
244244
line="1"
245-
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34480: Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/ma ...) (update to 2.25.4)"
245+
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34480: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging) (update to 2.25.4)"
246246
severity="warning"
247247
/>
248248
<error
249249
source="vulnerability_medium"
250250
line="1"
251-
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration) (update to 2.25.4)"
251+
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification) (update to 2.25.4)"
252252
severity="warning"
253253
/>
254254
</file>
@@ -269,13 +269,13 @@
269269
<error
270270
source="vulnerability_medium"
271271
line="14"
272-
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34480: Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/ma ...) (update to 2.25.4)"
272+
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34480: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging) (update to 2.25.4)"
273273
severity="warning"
274274
/>
275275
<error
276276
source="vulnerability_medium"
277277
line="14"
278-
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: Apache Log4j Core: `verifyHostName` attribute silently ignored in TLS configuration) (update to 2.25.4)"
278+
message="Insecure dependency maven/org.apache.logging.log4j/log4j-core@2.17.0 (CVE-2026-34477: org.apache.logging.log4j/log4j-core: Apache Log4j Core: Man-in-the-middle attack due to incomplete hostname verification) (update to 2.25.4)"
279279
severity="warning"
280280
/>
281281
</file>

0 commit comments

Comments
 (0)