Hakiri found a Ruby on Rails project with 93 production gems in the repo. The project has a total of 292 security warnings (289 in code and 3 in dependencies). Here is the breakdown of security warnings by type:
Attribute Restriction161 warnings |
Authenticationno warnings |
Buffer Errorsno warnings |
Code Injectionno warnings |
Command Injectionno warnings |
Configurationno warnings |
Credentials Managementno warnings |
Cross-Site Request Forgery3 warnings |
Cross-Site Scripting25 warnings |
Cryptographyno warnings |
Dangerous Evaluationno warnings |
Dangerous Send3 warnings |
Default Routesno warnings |
Denial of Service1 warning |
Dynamic Render Path1 warning |
File Access10 warnings |
Format Stringno warnings |
Format Validationno warnings |
Information Disclosureno warnings |
Input Validationno warnings |
Link Followingno warnings |
Mass Assignment48 warnings |
Numeric Errorsno warnings |
OS Command Injectionsno warnings |
Perms and Access Controlno warnings |
Race Conditionsno warnings |
Redirect11 warnings |
Resource Managementno warnings |
Session Settingno warnings |
SSL Verification Bypassno warnings |
SQL Injection29 warnings |
Unsafe Deserializationno warnings |
Otherno warnings |