Intentional vulnerable #32
4 new alerts including 3 high severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 3 high
- 1 medium
See annotations below for details.
Annotations
Check failure on line 39 in src/vulnerable-code/index.js
Code scanning / CodeQL
Missing rate limiting High
, but is not rate-limited.
Check warning on line 25 in src/vulnerable-code/index.js
Code scanning / CodeQL
Sensitive data read from GET request Medium
for GET requests uses query parameter as sensitive data.
Check failure on line 30 in src/vulnerable-code/index.js
Code scanning / CodeQL
Database query built from user-controlled sources High
.
Check failure on line 51 in src/vulnerable-code/index.js
Code scanning / CodeQL
Reflected cross-site scripting High
.