Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update HTTPServletResponse to ensure secure connections #14

Open
jordanpadams opened this issue Oct 17, 2019 · 0 comments
Open

Update HTTPServletResponse to ensure secure connections #14

jordanpadams opened this issue Oct 17, 2019 · 0 comments

Comments

@jordanpadams
Copy link
Member

PDS-000001 12/31/18 If possible always use setSecure to set the 'secure' flag on a cookie before adding it to an HttpServletResponse. high preparation/core/src/main/java/gov/nasa/pds/tools/util/Utility.java 96 Failure to use SSL (CWE-311) Failure to use SSL (CWE-311).  Non-SSL connections can be intercepted by third parties. Y Not using secure flag   3 CWE-311 Try to set secure before addCookie. ssoCookie.setSecure(true) plain text viewing possible if not set.
preparation/pds4-tools/src/main/java/gov/nasa/pds/label/object/DataObject.java 73 Failure to use SSL (CWE-311) Failure to use SSL (CWE-311).  Non-SSL connections can be intercepted by third parties. Y Not using secure flag   3 CWE-311 Try to set secure before addCookie. ssoCookie.setSecure(true) plain text viewing possible if not set.
preparation/pds4-tools/src/main/java/gov/nasa/pds/label/object/DataObject.java 120 Failure to use SSL (CWE-311) Failure to use SSL (CWE-311).  Non-SSL connections can be intercepted by third parties. Y Not using secure flag   3 CWE-311 Try to set secure before addCookie. ssoCookie.setSecure(true) plain text viewing possible if not set.
preparation/pds4-tools/src/main/java/gov/nasa/pds/objectAccess/ObjectAccess.java 253 Failure to use SSL (CWE-311) Failure to use SSL (CWE-311).  Non-SSL connections can be intercepted by third parties. Y Not using secure flag   3 CWE-311 Try to set secure before addCookie. ssoCookie.setSecure(true) plain text viewing possible if not set.
preparation/pds4-tools/src/main/java/gov/nasa/pds/objectAccess/utility/Utility.java 88 Failure to use SSL (CWE-311) Failure to use SSL (CWE-311).  Non-SSL connections can be intercepted by third parties. Y Not using secure flag   3 CWE-311 Try to set secure before addCookie. ssoCookie.setSecure(true) plain text viewing possible if not set.
report/report-manager/src/main/java/gov/nasa/pds/report/logs/pushpull/HttpPull.java 185 Failure to use SSL (CWE-311) Failure to use SSL (CWE-311).  Non-SSL connections can be intercepted by third parties. Y Not using secure flag   3 CWE-311 Try to set secure before addCookie. ssoCookie.setSecure(true) plain text viewing possible if not set.
transport/transport-proxy/src/main/java/gov/nasa/pds/portal/product/HTTPAdaptor.java 96 Failure to use SSL (CWE-311) Failure to use SSL (CWE-311).  Non-SSL connections can be intercepted by third parties. Y Not using secure flag   3 CWE-311 Try to set secure before addCookie. ssoCookie.setSecure(true) plain text viewing possible if not set.
transport/transport-proxy/src/main/java/gov/nasa/pds/portal/product/HTTPAdaptor.java 147 Failure to use SSL (CWE-311) Failure to use SSL (CWE-311).  Non-SSL connections can be intercepted by third parties. Y Not using secure flag   3 CWE-311 Try to set secure before addCookie. ssoCookie.setSecure(true) plain text viewing possible if not set.
transport/transport-proxy/src/main/java/gov/nasa/pds/portal/product/HTTPAdaptor.java 160 Failure to use SSL (CWE-311) Failure to use SSL (CWE-311).  Non-SSL connections can be intercepted by third parties. Y Not using secure flag   3 CWE-311 Try to set secure before addCookie. ssoCookie.setSecure(true) plain text viewing possible if not set.
transport/transport-registry/src/main/java/gov/nasa/pds/transport/SearchProductHandler.java 472 Failure to use SSL (CWE-311) Failure to use SSL (CWE-311).  Non-SSL connections can be intercepted by third parties. Y Not using secure flag   3 CWE-311 Try to set secure before addCookie. ssoCookie.setSecure(true) plain text viewing possible if not set.
transport/transport-registry/src/main/java/gov/nasa/pds/transport/SearchProductHandler.java 513 Failure to use SSL (CWE-311) Failure to use SSL (CWE-311).  Non-SSL connections can be intercepted by third parties. Y Not using secure flag   3 CWE-311 Try to set secure before addCookie. ssoCookie.setSecure(true) plain text viewing possible if not set.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: ToDo
Development

No branches or pull requests

3 participants