CRIT
MINED019
[MINED019] Ssti Jinja From String: jinja2.Environment().from_string(user_input) — full RC…
java-checks-test-sources/spring-3.2/src…:33
CRIT
MINED007
[MINED007] Sql String Concat: cursor.execute(f"... {user_input} ...") — SQL injection.
java-checks-test-sources/spring-3.2/src…:29
CRIT
SEC022
[SEC022] Database URL With Embedded Credential: A database connection URL contains an emb…
java-checks-test-sources/default/src/ma…:66
CRIT
MINED013
[MINED013] Password In Url: https://user:password@host — leaks creds via logs, referrer, …
java-checks-test-sources/default/src/ma…:66
CRIT
MINED013
[MINED013] Password In Url: https://user:password@host — leaks creds via logs, referrer, …
java-checks-test-sources/default/src/ma…:79
CRIT
SEC051
[SEC051] Stripe live/test key: Stripe API key (live or test). Live keys can charge real c…
java-checks-test-sources/default/src/ma…:103
CRIT
SEC001
[SEC001] Hardcoded Password: Hardcoded password found in source code.
java-checks-test-sources/default/src/ma…:43
HIGH
SEC106
[SEC106] Block cipher in ECB mode (AES/DES/Blowfish): ECB mode leaks block-level structur…
java-checks-test-sources/default/src/ma…:32
HIGH
SEC106
[SEC106] Block cipher in ECB mode (AES/DES/Blowfish): ECB mode leaks block-level structur…
java-checks-test-sources/default/src/ma…:19
HIGH
SEC102
[SEC102] Jackson default typing / polymorphic deserialization enabled: Jackson with defau…
java-checks-test-sources/default/src/ma…:13
HIGH
SEC100
[SEC100] CORS permissive Access-Control-Allow-Origin: *: Permissive CORS policy (`*` orig…
java-checks-test-sources/default/src/ma…:28
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
java-checks-test-sources/default/src/ma…:77
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
java-checks-test-sources/default/src/ma…:19
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
java-checks-test-sources/default/src/ma…:33
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
java-checks-test-sources/default/src/ma…:63
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
its/plugin/projects/struts-1.3.9-lite/c…:205
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
java-checks-common/src/main/java/org/so…:62
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
java-checks-aws/src/main/java/org/sonar…:33
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
its/plugin/projects/struts-1.3.9-lite/c…:208
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
its/plugin/projects/struts-1.3.9-lite/c…:61
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
its/plugin/projects/struts-1.3.9-lite/c…:78
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
its/plugin/projects/struts-1.3.9-lite/c…:166
HIGH
SEC030
[SEC030] Open Redirect — user-controlled redirect target: Redirect target is taken direct…
its/plugin/projects/struts-1.3.9-lite/c…:94
HIGH
MINED115
[MINED115] Action `SonarSource/ci-github-actions/config-maven` pinned to mutable ref `@v1…
.github/workflows/build.yml:88
HIGH
MINED115
[MINED115] Action `SonarSource/ci-github-actions/build-maven` pinned to mutable ref `@v1`…
.github/workflows/build.yml:37
HIGH
MINED115
[MINED115] Action `SonarSource/gh-action_releasability/releasability-status` pinned to mu…
.github/workflows/ReleasabilityCheck.yml:24
HIGH
MINED115
[MINED115] Action `SonarSource/gh-action_release/.github/workflows/main.yaml` pinned to m…
.github/workflows/release.yml:29
HIGH
MINED115
[MINED115] Action `actions/stale` pinned to mutable ref `@v9`: `uses: actions/stale@v9` r…
.github/workflows/mark-prs-stale.yml:14
HIGH
MINED115
[MINED115] Action `SonarSource/gh-action_dogfood_merge` pinned to mutable ref `@v1`: `use…
.github/workflows/dogfood.yml:31
HIGH
MINED115
[MINED115] Action `SonarSource/vault-action-wrapper` pinned to mutable ref `@v3`: `uses: …
.github/workflows/dogfood.yml:22
HIGH
MINED115
[MINED115] Action `SonarSource/gh-action_cache/cleanup` pinned to mutable ref `@v1`: `use…
.github/workflows/cleanup-cache.yml:29
HIGH
MINED115
[MINED115] Action `SonarSource/release-github-actions/create-pull-request` pinned to muta…
.github/workflows/PrepareNextIteration.…:42
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/PrepareNextIteration.…:21
HIGH
MINED115
[MINED115] Action `SonarSource/unified-dogfooding-actions/run-iris` pinned to mutable ref…
.github/workflows/unified-dogfooding.yml:29
HIGH
MINED115
[MINED115] Action `SonarSource/ci-github-actions/build-maven` pinned to mutable ref `@v1`…
.github/workflows/unified-dogfooding.yml:19
HIGH
MINED115
[MINED115] Action `sonarsource/gh-action-lt-backlog/ToggleLockBranch` pinned to mutable r…
.github/workflows/ToggleLockBranch.yml:19
HIGH
MINED115
[MINED115] Action `SonarSource/vault-action-wrapper` pinned to mutable ref `@v3`: `uses: …
.github/workflows/ToggleLockBranch.yml:14
HIGH
MINED115
[MINED115] Action `sonarsource/gh-action-lt-backlog/SubmitReview` pinned to mutable ref `…
.github/workflows/SubmitReview.yml:26
HIGH
MINED115
[MINED115] Action `SonarSource/vault-action-wrapper` pinned to mutable ref `@v3`: `uses: …
.github/workflows/SubmitReview.yml:20
HIGH
MINED115
[MINED115] Action `SonarSource/gh-action_releasability` pinned to mutable ref `@v3`: `use…
.github/workflows/releasability.yaml:46
HIGH
MINED115
[MINED115] Action `SonarSource/vault-action-wrapper` pinned to mutable ref `@v3`: `uses: …
.github/workflows/releasability.yaml:21
HIGH
MINED115
[MINED115] Action `sonarsource/gh-action-lt-backlog/PullRequestClosed` pinned to mutable …
.github/workflows/PullRequestClosed.yml:24
HIGH
MINED115
[MINED115] Action `SonarSource/vault-action-wrapper` pinned to mutable ref `@v3`: `uses: …
.github/workflows/PullRequestClosed.yml:19
HIGH
MINED115
[MINED115] Action `SonarSource/ci-github-actions/pr_cleanup` pinned to mutable ref `@v1`:…
.github/workflows/pr-cleanup.yml:12
HIGH
MINED115
[MINED115] Action `SonarSource/release-github-actions/.github/workflows/automated-release…
.github/workflows/automated-release.yml:46
HIGH
MINED115
[MINED115] Action `SonarSource/release-github-actions/update-rule-metadata` pinned to mut…
.github/workflows/UpdateRuleMetadata.yml:15
HIGH
MINED115
[MINED115] Action `sonarsource/gh-action-lt-backlog/PullRequestCreated` pinned to mutable…
.github/workflows/PullRequestCreated.yml:24
HIGH
MINED115
[MINED115] Action `SonarSource/vault-action-wrapper` pinned to mutable ref `@v3`: `uses: …
.github/workflows/PullRequestCreated.yml:18
HIGH
JRN004
Consent is collected in UI without visible backend audit persistence
sonar-java-plugin/src/main/resources/or…:8
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
java-checks-test-sources/default/src/ma…:16
MED
SEC031
[SEC031] Catastrophic Backtracking Regex (ReDoS): Regex contains nested quantifiers like …
java-checks/src/main/java/org/sonar/jav…:54
MED
SEC031
[SEC031] Catastrophic Backtracking Regex (ReDoS): Regex contains nested quantifiers like …
java-checks-test-sources/default/src/ma…:8
MED
SEC031
[SEC031] Catastrophic Backtracking Regex (ReDoS): Regex contains nested quantifiers like …
java-checks-test-sources/default/src/ma…:8
MED
SEC107
[SEC107] Weak TLS version requested (TLSv1.0, TLSv1.1, SSLv3, SSLv2): TLS 1.0 and 1.1 wer…
java-checks-test-sources/default/src/ma…:12
MED
SEC107
[SEC107] Weak TLS version requested (TLSv1.0, TLSv1.1, SSLv3, SSLv2): TLS 1.0 and 1.1 wer…
java-checks-test-sources/default/src/ma…:19
MED
SEC087
[SEC087] JS: weak Math.random for crypto: Math.random() is not cryptographically secure; …
java-checks-test-sources/default/src/ma…:15
MED
SEC123
[SEC123] Production stack trace / debug output exposed: Debug mode left on in production …
java-checks-test-sources/default/src/ma…:7
MED
SEC105
[SEC105] Cookie missing HttpOnly/Secure flag: Session cookie missing HttpOnly (allows JS …
java-checks-test-sources/default/src/ma…:37
MED
SEC105
[SEC105] Cookie missing HttpOnly/Secure flag: Session cookie missing HttpOnly (allows JS …
java-checks-test-sources/default/src/ma…:28
MED
SEC105
[SEC105] Cookie missing HttpOnly/Secure flag: Session cookie missing HttpOnly (allows JS …
java-checks-test-sources/default/src/ma…:19
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
java-checks/src/main/java/org/sonar/jav…:66
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
java-checks-test-sources/default/src/ma…:56
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
java-checks-test-sources/default/src/ma…:19
MED
AUC001
[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
—
MED
JRN003
Frontend API reference is not matched by discovered backend routes
sonar-java-plugin/src/main/resources/or…:113
MED
JRN003
Frontend API reference is not matched by discovered backend routes
sonar-java-plugin/src/main/resources/or…:103
MED
JRN003
Frontend API reference is not matched by discovered backend routes
sonar-java-plugin/src/main/resources/or…:37
MED
JRN003
Frontend API reference is not matched by discovered backend routes
sonar-java-plugin/src/main/resources/or…:32
MED
JRN003
Frontend API reference is not matched by discovered backend routes
sonar-java-plugin/src/main/resources/or…:25
MED
JRN003
Frontend API reference is not matched by discovered backend routes
sonar-java-plugin/src/main/resources/or…:20
MED
JRN003
Frontend API reference is not matched by discovered backend routes
sonar-java-plugin/src/main/resources/or…:6
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
java-checks-test-sources/default/src/ma…:77
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
java-checks-test-sources/default/src/ma…:72
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
java-checks-test-sources/default/src/ma…:202
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
its/plugin/projects/struts-1.3.9-lite/c…:215
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
its/plugin/projects/struts-1.3.9-lite/c…:77
LOW
SEC132
[SEC132] String concat where the language has interpolation (AI style drift): String buil…
check-list/src/main/java/org/sonar/java…:56
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:61
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:49
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:48
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:78
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:76
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:17
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:16
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:41
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:30
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:107
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:59
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:36
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:131
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:41
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:129
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:33
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:74
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:13
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:49
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:25
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:6
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:7
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:64
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:10
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:539
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/t…:344
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/c…:26
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/c…:32
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/c…:20
LOW
AIC003
Duplicated implementation block across source files
its/plugin/projects/struts-1.3.9-lite/c…:159
INFO
MINED093
[MINED093] Java Sql Statement Concat: Statement.executeQuery with concat string = SQL inj…
java-checks-test-sources/default/src/ma…:27
INFO
MINED047
[MINED047] Emoji In Source: Emoji ✅ ❌ 🚀 in code/comments — common AI output unless explic…
java-checks-test-sources/default/src/ma…:4
INFO
MINED047
[MINED047] Emoji In Source: Emoji ✅ ❌ 🚀 in code/comments — common AI output unless explic…
java-checks-test-sources/default/src/ma…:47
INFO
MINED047
[MINED047] Emoji In Source: Emoji ✅ ❌ 🚀 in code/comments — common AI output unless explic…
java-checks-test-sources/default/src/ma…:46
INFO
MINED069
[MINED069] Debug True Prod: Django/Flask DEBUG=True or app.debug=True in non-test files.
java-checks-test-sources/default/src/ma…:7
INFO
MINED083
[MINED083] Java Thread Start: Raw thread creation. Should use ExecutorService for managed…
java-checks-test-sources/default/src/ma…:45
INFO
MINED083
[MINED083] Java Thread Start: Raw thread creation. Should use ExecutorService for managed…
java-checks-test-sources/default/src/ma…:198
INFO
MINED083
[MINED083] Java Thread Start: Raw thread creation. Should use ExecutorService for managed…
java-checks-test-sources/default/src/ma…:5
INFO
MINED092
[MINED092] Java Runtime Exec: Runtime.getRuntime().exec(cmd) with concat string args = co…
java-checks-test-sources/default/src/ma…:19
INFO
MINED085
[MINED085] Java Systemexit: System.exit() inside a library kills the whole JVM.
java-checks-test-sources/default/src/ma…:27
INFO
MINED085
[MINED085] Java Systemexit: System.exit() inside a library kills the whole JVM.
java-checks-test-sources/default/src/ma…:334
INFO
MINED085
[MINED085] Java Systemexit: System.exit() inside a library kills the whole JVM.
java-checks-test-sources/default/src/ma…:9
INFO
MINED053
[MINED053] Placeholder Default Username: [email protected] / [email protected] / admin/admin…
java-checks-test-sources/default/src/ma…:6
INFO
MINED053
[MINED053] Placeholder Default Username: [email protected] / [email protected] / admin/admin…
java-checks-test-sources/default/src/ma…:3
INFO
MINED053
[MINED053] Placeholder Default Username: [email protected] / [email protected] / admin/admin…
java-checks-test-sources/default/src/ma…:1
INFO
MINED081
[MINED081] Java Printstacktrace: Should use logger, not stack trace to stderr.
its/plugin/projects/struts-1.3.9-lite/t…:176
INFO
MINED081
[MINED081] Java Printstacktrace: Should use logger, not stack trace to stderr.
its/plugin/projects/struts-1.3.9-lite/t…:84
INFO
MINED081
[MINED081] Java Printstacktrace: Should use logger, not stack trace to stderr.
its/plugin/projects/struts-1.3.9-lite/t…:276
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
java-checks-test-sources/default/src/ma…:79
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
java-checks-test-sources/default/src/ma…:22
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
its/plugin/projects/struts-1.3.9-lite/t…:124