nathanjackson / cs7140-ditaa

Private copy of DITAA for CS7140.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

HP Fortify Results

MrNewFloppy opened this issue · comments

Critical

  • ConfigurationParser.java:75 (Path Manipulation)
  • ConfigurationParser.java:90 (Path Manipulation)
  • ConfigurationParser.java:106 (Path Manipulation)
  • ConfigurationParser.java:127 (Shared Sink)
  • ConfigurationParser.java:141 (Path Manipulation)

High

  • FileUtils.java:44 (Shared Sink)

  • FileUtils.java:141 (Portability Flaw: File Separator)

  • FileUtils.java:142 (Portability Flaw: File Separator)

  • FileUtils.java:145 (Portability Flaw: File Separator)

  • FileUtils.java:66 (Shared Sink)

  • FileUtils.java:146 (Portability Flaw: File Separator)

  • FileUtils.java:147 (Portability Flaw: File Separator)

  • ConfigurationParser.java:184 (Portability Flaw: Locale Dependent Comparison)

  • Command Line Converter.java:236 (Unreleased Resource: Streams)

  • Command Line Converter.java:24 (Unreleased Resource: Streams)

  • FileUtils.java:93 (Unreleased Resource: Streams)

  • HTMLConverter.java:83 (Unreleased Resource: Streams)

  • HTMLConverter.java:147 (Unreleased Resource: Streams)

  • HTMLConverter.java:197 (Unreleased Resource: Streams)

  • TextGrid.java:1514 (Unreleased Resource: Streams)

  • VisualTester.java:235 (Unreleased Resource: Streams)

  • VisualTester.java:281 (Unreleased Resource: Streams)

  • ConfigurationParser.java:67 (XML External Entity Injection)

  • DocBookConverter.java:61 (XML External Entity Injection)

Low (368 Total)

  • Dead Code