Author | TrackMe Limited, U.K. |
---|---|
Tags | cloud |
Version | 1.0.6 |
Hash | 1900ff2e42082d5d27157d10175250d2 |
AppInspect Request ID | 58dd5f61-fdeb-4cd2-89c0-31bc353aab81 |
Run Time | 2025-04-08T06:24:03.714924 |
Execution Time | 110 |
Field | Value |
---|---|
AppInspect Version | 3.9.1 |
Name | Version | Is Latest |
---|---|---|
dynamic-checks | 1.37.1 | True |
retire-js | 1.1.0 | True |
static-checks | 3.9.1 | True |
Status | Count |
---|---|
Successes
|
132 |
Failures
|
0 |
Errors
|
0 |
Warnings
|
14 |
Manual Checks Outstanding
|
11 |
Not Applicable
|
91 |
Skipped
|
0 |
This vulnerability impacts npm (server) users of moment.js, especially if user provided locale string, eg fr is directly used to switch moment locale.
Regular Expression Denial of Service (ReDoS), Affecting moment package, versions >=2.18.0 <2.29.4
Custom config file default/ta_trackme_cribl_settings.conf is detected in this app. By default, it will be partitioned to all instances including Search Head(s), Indexer(s) and Forwarder(s). If that's not what you expect, you can use the `targetWorkloads` attribute in app.manifest to indicate the correct instances. For more details about app.manifest, please refer to https://dev.splunk.com/enterprise/docs/releaseapps/packagingtoolkit/pkgtoolkitref/pkgtoolkitapp#JSON-schema-200. Please also make sure that this custom file is safe to install.
27Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize the Unified Dashboard Framework (UDF). Please ignore this warning as it has no impact to your Splunk app. Match: @splunk/dashboard-layouts
3183Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize the Unified Dashboard Framework (UDF). Please ignore this warning as it has no impact to your Splunk app. Match: @splunk/dashboard-layouts
2195Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize Splunk UI utility components. Please ignore this warning as it has no impact to your Splunk app. Match: @splunk/moment
2Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize SplunkJS. Please ignore this warning as it has no impact to your Splunk app. Match: splunkjs/mvc
2305Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize Splunk UI. Please ignore this warning as it has no impact to your Splunk app. Match: @splunk/react-icons
2As of Splunk 6.5, this functionality is deprecated and should be removed in futureapp versions. Match: splunkjs/mvc/headerview.
Update Mako templates to be Python 3-compatible. Splunk Web, which Mako templates depend on, will support only Python 3.7. If you've finished your update, please disregard this message.
178 Python files found. Update these Python scripts to be cross-compatible with Python 2 and 3 for Splunk Enterprise 8.0. See https://docs.splunk.com/Documentation/Splunk/latest/Python3Migration/AboutMigration for more information. If you've finished your update, please disregard this message.
23Found a prohibited character in [(?::){0}cribl:custom_commands:*] stanza in props.conf. Special characters <>?&# are not allowed. Rename the stanza to not contain any forbidden characters.
33Splunk SDK for Python detected (version 2.1.0). No action required at this time.
139The following line contains subprocess.Popen.communicate usage. Use threading and multiprocessing with discretion.
139The following line contains subprocess.Popen usage. Use threading and multiprocessing with discretion.
320The following line contains subprocess.Popen.communicate usage. Use threading and multiprocessing with discretion.
166The following line contains questionable usage `threading.Thread.start` in loop. Use threading and multiprocessing with discretion.
317The following line contains subprocess.Popen usage. Use threading and multiprocessing with discretion.
146Bias language is found in the app. .. image:: https://ci.appveyor.com/api/projects/status/github/gra... (lib/sortedcontainers-2.4.0.dist-info/METADATA:146) [master].
46Bias language is found in the app. .. image:: https://codecov.io/github/tiran/defusedxml/coverage.sv... (lib/defusedxml-0.7.1.dist-info/METADATA:46) [master].
47Bias language is found in the app. :target: https://codecov.io/github/tiran/defusedxml?branch=<<<MAS... (lib/defusedxml-0.7.1.dist-info/METADATA:47) [master].
100Bias language is found in the app. for key in ("apps", "slave-apps", "<<<MASTER>>>-apps"): (lib/splunktaucclib/legacy/util.py:100) [master].
760Bias language is found in the app. and release. The <<<MASTER>>> branch received the same fix in Pul... (lib/urllib3-1.26.20.dist-info/METADATA:760) [master].
1584Bias language is found in the app. `,Ut=(e,t=!1)=>{const r=void 0===(0,x.get)(e,"primary.data.column... (appserver/static/js/build/573.5fd2479619ebddbe9e59.js:1584) [master].
41Bias language is found in the app. for key in ("apps", "slave-apps", "<<<MASTER>>>-apps"): (lib/splunktaucclib/rest_handler/util.py:41) [master].
37Bias language is found in the app. # <<<BLACKLIST>>> = (etree._Entity, etree._ProcessingInstruction,... (lib/defusedxml/lxml.py:37) [blacklist].
27Bias language is found in the app. `,br=({level:e="info",message:t="",centered:r=!0})=>D.createEleme... (appserver/static/js/build/573.5fd2479619ebddbe9e59.js:27) [master].
38Bias language is found in the app. <<<BLACKLIST>>> = _etree._Entity (lib/defusedxml/lxml.py:38) [blacklist].
43Bias language is found in the app. if isinstance(child, <<<BLACKLIST>>>): (lib/defusedxml/lxml.py:43) [blacklist].
41Bias language is found in the app. for key in ("apps", "<<<SLAVE>>>-apps", "master-apps"): (lib/splunktaucclib/rest_handler/util.py:41) [slave].
2110Bias language is found in the app. `,R=class extends b.PureComponent{constructor(e){super(e),this.st... (appserver/static/js/build/573.5fd2479619ebddbe9e59.js:2110) [master].
125Bias language is found in the app. groups_url = f"/api/v1/<<<MASTER>>>/groups?product=stream" (bin/cribl.py:125) [master].
100Bias language is found in the app. for key in ("apps", "<<<SLAVE>>>-apps", "master-apps"): (lib/splunktaucclib/legacy/util.py:100) [slave].
143Bias language is found in the app. .. image:: https://api.travis-ci.org/grantjenks/python-sortedcont... (lib/sortedcontainers-2.4.0.dist-info/METADATA:143) [master].
42Bias language is found in the app. .. image:: https://travis-ci.org/tiran/defusedxml.svg?branch=<<<M... (lib/defusedxml-0.7.1.dist-info/METADATA:42) [master].
249Bias language is found in the app. * https://github.com/foliojs/pdfkit/blob/<<<MASTER>>>/lib/securit... (appserver/static/js/build/573.5fd2479619ebddbe9e59.js.LICENSE.txt:249) [master].
41Bias language is found in the app. <<<BLACKLIST>>> = self.<<<BLACKLIST>>> (lib/defusedxml/lxml.py:41) [blacklist].
710Bias language is found in the app. was not in the method <<<WHITELIST>>>. (Issue #1059) (lib/urllib3-1.26.20.dist-info/METADATA:710) [whitelist].
2PUBLIC IP 1.49.255.68 is found in appserver/static/js/build/242.da2e3dbe1c85f0cd0e92.js:2
70PUBLIC IP 5.5.5.5 is found in lib/PySocks-1.7.1.dist-info/METADATA:70
27PUBLIC IP 1.49.255.68 is found in appserver/static/js/build/573.5fd2479619ebddbe9e59.js:27
This vulnerability impacts npm (server) users of moment.js, especially if user provided locale string, eg fr is directly used to switch moment locale.
Regular Expression Denial of Service (ReDoS), Affecting moment package, versions >=2.18.0 <2.29.4
Custom config file default/ta_trackme_cribl_settings.conf is detected in this app. By default, it will be partitioned to all instances including Search Head(s), Indexer(s) and Forwarder(s). If that's not what you expect, you can use the `targetWorkloads` attribute in app.manifest to indicate the correct instances. For more details about app.manifest, please refer to https://dev.splunk.com/enterprise/docs/releaseapps/packagingtoolkit/pkgtoolkitref/pkgtoolkitapp#JSON-schema-200. Please also make sure that this custom file is safe to install.
No ../.dependencies folder found. Please check that the Splunk App package contains only valid dependencies.
No ../.dependencies folder found. Please add a .dependencies directory with an valid app folder.
Didn't find any flash files.
No ../.dependencies folder found. Please add a .dependencies directory that contains an app folder with an app.manifest.
authentication.conf does not exist
authentication.conf does not exist
authentication.conf does not exist
alert_actions.conf does not exist
data/ui/manager does not exist
distsearch.conf does not exist
indexes.conf does not exist
inputs.conf does not exist
inputs.conf does not exist
The `lookups` directory does not exist.
inputs.conf does not exist
authentication.conf does not exist
audit.conf does not exist
bookmarks.conf does not exist
datatypesbnf.conf does not exist
default-mode.conf does not exist
deploymentclient.conf does not exist
deployment.conf does not exist
indexes.conf.conf does not exist
inputs.conf.conf does not exist
No java files found in app.
No Perl scripts found in app.
health.conf does not exist
inputs.conf.conf does not exist
inputs.conf does not exist
inputs.conf does not exist
inputs.conf does not exist
inputs.conf.conf does not exist
inputs.conf does not exist
inputs.conf does not exist
inputs.conf.conf does not exist
inputs.conf does not exist
instance.cfg.conf does not exist
crawl.conf does not exist
literals.conf does not exist
messages.conf does not exist
No `inputs.conf.spec` was detected.
passwords.conf does not exist
pubsub.conf does not exist
`inputs.conf` does not exist.
segmenters.conf does not exist
serverclass.conf does not exist
serverclass.seed.xml.conf does not exist
source-classifier.conf does not exist
sourcetypes.conf does not exist
splunk-launch.conf does not exist
telemetry.conf does not exist
`default/transforms.conf` does not exist.
user-seed.conf does not exist
wmi.conf does not exist
workload_pools.conf does not exist
workload_rules.conf does not exist
27Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize the Unified Dashboard Framework (UDF). Please ignore this warning as it has no impact to your Splunk app. Match: @splunk/dashboard-layouts
3183Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize the Unified Dashboard Framework (UDF). Please ignore this warning as it has no impact to your Splunk app. Match: @splunk/dashboard-layouts
2195Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize Splunk UI utility components. Please ignore this warning as it has no impact to your Splunk app. Match: @splunk/moment
2Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize SplunkJS. Please ignore this warning as it has no impact to your Splunk app. Match: splunkjs/mvc
2305Splunk has begun gathering telemetry on apps submitted to appinspect, that utilize Splunk UI. Please ignore this warning as it has no impact to your Splunk app. Match: @splunk/react-icons
2705The following line will be inspected during code review. Match: eval(t
`default/setup.xml` does not exist. The stored xss check is not applicable
limits.conf does not exist
outputs.conf does not exist
data/spl2 does not exist
eventtypes.conf does not exist
crawl.conf does not exist
viewstates.conf does not exist
savedsearches.conf does not exist
outputs.conf does not exist
literals.conf does not exist
Update Mako templates to be Python 3-compatible. Splunk Web, which Mako templates depend on, will support only Python 3.7. If you've finished your update, please disregard this message.
178 Python files found. Update these Python scripts to be cross-compatible with Python 2 and 3 for Splunk Enterprise 8.0. See https://docs.splunk.com/Documentation/Splunk/latest/Python3Migration/AboutMigration for more information. If you've finished your update, please disregard this message.
No `inputs.conf.spec` file exists.
lookups folder does not exist
savedsearches.conf does not exist
savedsearches.conf does not exist
savedsearches.conf does not exist
savedsearches.conf does not exist
savedsearches.conf does not exist
savedsearches.conf does not exist
`local/app.conf` does not exist.
`local/app.conf` does not exist.
The local directory does not exist.
collections.conf does not exist
indexes.conf does not exist
indexes.conf does not exist
indexes.conf does not exist
indexes.conf does not exist
23Found a prohibited character in [(?::){0}cribl:custom_commands:*] stanza in props.conf. Special characters <>?&# are not allowed. Rename the stanza to not contain any forbidden characters.
No INGEST_EVAL properties were declared.
No `alert_actions.conf` was detected.
workflow_actions.conf does not exist
datamodels.conf does not exist
No forbidden python files were found.
33Splunk SDK for Python detected (version 2.1.0). No action required at this time.
481The following line will be inspected during code review. The `__builtin__.open` module/method can be used to manipulate files outside of the app dir.
235The following line will be inspected during code review. The `__builtin__.open` module/method can be used to manipulate files outside of the app dir.
46The following line will be inspected during code review. The `__builtin__.open` module/method can be used to manipulate files outside of the app dir.
355The following line will be inspected during code review. The `__builtin__.open` module/method can be used to manipulate files outside of the app dir.
26The following line will be inspected during code review. The `__builtin__.open` module/method can be used to manipulate files outside of the app dir.
739The following line will be inspected during code review. The `__builtin__.open` module/method can be used to manipulate files outside of the app dir.
24The following line will be inspected during code review. The `__builtin__.open` module/method can be used to manipulate files outside of the app dir.
253The following line will be inspected during code review. The `__builtin__.open` module/method can be used to manipulate files outside of the app dir.
100The following line will be inspected during code review. The __builtin__.eval module/method can be used to execute arbitrary expression.
185The following line will be inspected during code review. The `__builtin__.open` module/method can be used to manipulate files outside of the app dir.
128The following line will be inspected during code review. The `__builtin__.open` module/method can be used to manipulate files outside of the app dir.
163The following lines should be inspected during code review, `gzip.open` could be used to create an archiving object, it can read or write file outside of app dir.
174The following lines should be inspected during code review, `gzip.open` could be used to create an archiving object, it can read or write file outside of app dir.
538The following line will be inspected during code review. The `tempfile.mkdtemp` module/method can be used to access file/directory outside of the app dir. Function call arguments: [], keywords: {}
139The following line will be inspected during code review. The `os.fdopen` module/method can be used to access file/directory outside of the app dir. Function call arguments: ["?", "wb", "?"], keywords: {}
244The following line will be inspected during code review. The `os.rename` module/method can be used to access file/directory outside of the app dir. Function call arguments: ["?_new", "?"], keywords: {}
540The following line will be inspected during code review. The `os.makedirs` module/method can be used to access file/directory outside of the app dir. Function call arguments: ["?"], keywords: {}
240The following line will be inspected during code review. The `os.remove` module/method can be used to access file/directory outside of the app dir. Function call arguments: ["?"], keywords: {}
261The following line will be inspected during code review. The `os.remove` module/method can be used to access file/directory outside of the app dir. Function call arguments: ["?"], keywords: {}
129The following lines should be inspected during code review. `logging.handlers.RotatingFileHandler` could be used to receive data from outside or log data to outside.
25The following lines should be inspected during code review. `logging.handlers.RotatingFileHandler` could be used to receive data from outside or log data to outside.
30The following lines should be inspected during code review. `logging.StreamHandler` could be used to receive data from outside or log data to outside.
967The following lines should be inspected during code review. `logging.handlers.RotatingFileHandler` could be used to receive data from outside or log data to outside.
187The following lines should be inspected during code review. `logging.handlers.RotatingFileHandler` could be used to receive data from outside or log data to outside.
37The following lines should be inspected during code review. `logging.handlers.RotatingFileHandler` could be used to receive data from outside or log data to outside.
139The following lines should be inspected during code review, Possible plain text credentials disclosure here, `self.ENCRYPTED_TOKEN = ******`
82The following lines should be inspected during code review, Possible plain text credentials disclosure here, `self._code = 500`
167The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_ENABLE_KEY = proxy_enabled`
4The following lines should be inspected during code review, Possible plain text credentials disclosure here, `__author__ = TrackMe Limited U.K`
247The following lines should be inspected during code review, Possible plain text credentials disclosure here, `LOG_LEVEL_KEY = loglevel`
71The following lines should be inspected during code review, Possible plain text credentials disclosure here, `code = 500`
95The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PASSWORD = ******`
73The following lines should be inspected during code review, Possible plain text credentials disclosure here, `OBJ_PERMS_DELETE_KEY = delete`
6The following lines should be inspected during code review, Possible plain text credentials disclosure here, `__author__ = TrackMe Limited`
227The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_ENABLE_KEY = proxy_enabled`
230The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_RDNS_KEY = proxy_rdns`
67The following lines should be inspected during code review, Possible plain text credentials disclosure here, `OBJ_TYPE_KEY = obj_type`
75The following lines should be inspected during code review, Possible plain text credentials disclosure here, `OBJ_SHARED_BY_INCLUSION_KEY = obj_shared_by_inclusion`
88The following lines should be inspected during code review, Possible plain text credentials disclosure here, `LOG_LEVEL_KEY_ENV = log_level`
229The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_RDNS_KEY = proxy_rdns`
170The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_ENABLE_KEY = proxy_enabled`
151The following lines should be inspected during code review, Possible plain text credentials disclosure here, `GLOBAL_SETTING_KEY = global_settings`
71The following lines should be inspected during code review, Possible plain text credentials disclosure here, `OBJ_PERMS_READ_KEY = read`
168The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_RDNS_KEY = proxy_rdns`
15The following lines should be inspected during code review, Possible plain text credentials disclosure here, `__author__ = Donald Stufft and individual contributors`
6The following lines should be inspected during code review, Possible plain text credentials disclosure here, `__author__ = TrackMe Limited`
172The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_RDNS_KEY = proxy_rdns`
70The following lines should be inspected during code review, Possible plain text credentials disclosure here, `OBJ_PERMS_KEY = obj_perms`
85The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_ENABLE_KEY = proxy_enabled`
48The following lines should be inspected during code review, Possible plain text credentials disclosure here, `ENCRYPTED_TOKEN = ******`
86The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_RDNS_KEY = proxy_rdns`
71The following lines should be inspected during code review, Possible plain text credentials disclosure here, `self._code = 500`
258The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_ENABLE_KEY = proxy_enabled`
87The following lines should be inspected during code review, Possible plain text credentials disclosure here, `LOG_LEVEL_KEY = loglevel`
101The following lines should be inspected during code review, Possible plain text credentials disclosure here, `self._code = 500`
100The following lines should be inspected during code review, Possible plain text credentials disclosure here, `self._code = 500`
321The following lines should be inspected during code review, Possible plain text credentials disclosure here, `clear_password = `
285The following lines should be inspected during code review, Possible plain text credentials disclosure here, `clear_password = `
69The following lines should be inspected during code review, Possible plain text credentials disclosure here, `GLOBAL_SETTING_KEY = global_settings`
385The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_ENABLE_KEY = proxy_enabled`
214The following lines should be inspected during code review, Possible plain text credentials disclosure here, `self.PASSWORD = ******`
69The following lines should be inspected during code review, Possible plain text credentials disclosure here, `OBJ_OWNER_KEY = obj_owner`
66The following lines should be inspected during code review, Possible plain text credentials disclosure here, `OBJ_ID_KEY = obj_id`
65The following lines should be inspected during code review, Possible plain text credentials disclosure here, `OBJ_COLLECTION_KEY = obj_collection`
11The following lines should be inspected during code review, Possible plain text credentials disclosure here, `__author__ = Donald Stufft and individual contributors`
73The following lines should be inspected during code review, Possible plain text credentials disclosure here, `code = 500`
68The following lines should be inspected during code review, Possible plain text credentials disclosure here, `OBJ_APP_KEY = obj_app`
85The following lines should be inspected during code review, Possible plain text credentials disclosure here, `self._code = 500`
226The following lines should be inspected during code review, Possible plain text credentials disclosure here, `PROXY_ENABLE_KEY = proxy_enabled`
221The following lines should be inspected during code review, Possible plain text credentials disclosure here, `LOG_LEVEL_KEY = loglevel`
72The following lines should be inspected during code review, Possible plain text credentials disclosure here, `OBJ_PERMS_WRITE_KEY = write`
286The following lines should be inspected during code review, Possible plain text credentials disclosure here, `encr_password = `
176The following lines should be inspected during code review, Possible plain text credentials disclosure here, `LOG_LEVEL_KEY_ENV = log_level`
139The following line contains subprocess.Popen.communicate usage. Use threading and multiprocessing with discretion.
139The following line contains subprocess.Popen usage. Use threading and multiprocessing with discretion.
320The following line contains subprocess.Popen.communicate usage. Use threading and multiprocessing with discretion.
166The following line contains questionable usage `threading.Thread.start` in loop. Use threading and multiprocessing with discretion.
317The following line contains subprocess.Popen usage. Use threading and multiprocessing with discretion.
Python httplib2 library not found.
addon_builder.conf does not exist
146Bias language is found in the app. .. image:: https://ci.appveyor.com/api/projects/status/github/gra... (lib/sortedcontainers-2.4.0.dist-info/METADATA:146) [master].
46Bias language is found in the app. .. image:: https://codecov.io/github/tiran/defusedxml/coverage.sv... (lib/defusedxml-0.7.1.dist-info/METADATA:46) [master].
47Bias language is found in the app. :target: https://codecov.io/github/tiran/defusedxml?branch=<<<MAS... (lib/defusedxml-0.7.1.dist-info/METADATA:47) [master].
100Bias language is found in the app. for key in ("apps", "slave-apps", "<<<MASTER>>>-apps"): (lib/splunktaucclib/legacy/util.py:100) [master].
760Bias language is found in the app. and release. The <<<MASTER>>> branch received the same fix in Pul... (lib/urllib3-1.26.20.dist-info/METADATA:760) [master].
1584Bias language is found in the app. `,Ut=(e,t=!1)=>{const r=void 0===(0,x.get)(e,"primary.data.column... (appserver/static/js/build/573.5fd2479619ebddbe9e59.js:1584) [master].
41Bias language is found in the app. for key in ("apps", "slave-apps", "<<<MASTER>>>-apps"): (lib/splunktaucclib/rest_handler/util.py:41) [master].
37Bias language is found in the app. # <<<BLACKLIST>>> = (etree._Entity, etree._ProcessingInstruction,... (lib/defusedxml/lxml.py:37) [blacklist].
27Bias language is found in the app. `,br=({level:e="info",message:t="",centered:r=!0})=>D.createEleme... (appserver/static/js/build/573.5fd2479619ebddbe9e59.js:27) [master].
38Bias language is found in the app. <<<BLACKLIST>>> = _etree._Entity (lib/defusedxml/lxml.py:38) [blacklist].
43Bias language is found in the app. if isinstance(child, <<<BLACKLIST>>>): (lib/defusedxml/lxml.py:43) [blacklist].
41Bias language is found in the app. for key in ("apps", "<<<SLAVE>>>-apps", "master-apps"): (lib/splunktaucclib/rest_handler/util.py:41) [slave].
2110Bias language is found in the app. `,R=class extends b.PureComponent{constructor(e){super(e),this.st... (appserver/static/js/build/573.5fd2479619ebddbe9e59.js:2110) [master].
125Bias language is found in the app. groups_url = f"/api/v1/<<<MASTER>>>/groups?product=stream" (bin/cribl.py:125) [master].
100Bias language is found in the app. for key in ("apps", "<<<SLAVE>>>-apps", "master-apps"): (lib/splunktaucclib/legacy/util.py:100) [slave].
143Bias language is found in the app. .. image:: https://api.travis-ci.org/grantjenks/python-sortedcont... (lib/sortedcontainers-2.4.0.dist-info/METADATA:143) [master].
42Bias language is found in the app. .. image:: https://travis-ci.org/tiran/defusedxml.svg?branch=<<<M... (lib/defusedxml-0.7.1.dist-info/METADATA:42) [master].
249Bias language is found in the app. * https://github.com/foliojs/pdfkit/blob/<<<MASTER>>>/lib/securit... (appserver/static/js/build/573.5fd2479619ebddbe9e59.js.LICENSE.txt:249) [master].
41Bias language is found in the app. <<<BLACKLIST>>> = self.<<<BLACKLIST>>> (lib/defusedxml/lxml.py:41) [blacklist].
710Bias language is found in the app. was not in the method <<<WHITELIST>>>. (Issue #1059) (lib/urllib3-1.26.20.dist-info/METADATA:710) [whitelist].
2PUBLIC IP 1.49.255.68 is found in appserver/static/js/build/242.da2e3dbe1c85f0cd0e92.js:2
70PUBLIC IP 5.5.5.5 is found in lib/PySocks-1.7.1.dist-info/METADATA:70
27PUBLIC IP 1.49.255.68 is found in appserver/static/js/build/573.5fd2479619ebddbe9e59.js:27
58Environment variable being used in lib/solnlib/splunkenv.py:58: os.environ.
61Environment variable being used in lib/solnlib/utils.py:61: os.environ.
164Environment variable being used in lib/splunktaucclib/modinput_wrapper/base_modinput.py:164: os.environ.get.
92Environment variable being used in lib/splunktaucclib/legacy/util.py:92: os.environ.
537Environment variable being used in lib/splunktaucclib/modinput_wrapper/base_modinput.py:537: os.environ.
198Environment variable being used in lib/solnlib/splunkenv.py:198: os.environ.
307Environment variable being used in lib/solnlib/splunkenv.py:307: os.environ.
222Environment variable being used in lib/splunktaucclib/modinput_wrapper/base_modinput.py:222: os.environ.get.
21Environment variable being used in bin/cribl_rest_handler.py:21: os.environ.
63Environment variable being used in lib/solnlib/splunkenv.py:63: os.environ.
91Environment variable being used in lib/splunktaucclib/legacy/util.py:91: os.environ.
113Environment variable being used in lib/splunktaucclib/rest_handler/util.py:113: os.environ.
32Environment variable being used in lib/cribl_libs.py:32: os.environ.
60Environment variable being used in lib/solnlib/utils.py:60: os.environ.
111Environment variable being used in lib/splunktaucclib/rest_handler/util.py:111: os.environ.
112Environment variable being used in lib/splunktaucclib/rest_handler/util.py:112: os.environ.
357Environment variable being used in lib/urllib3/util/ssl_.py:357: os.environ.get.
138Environment variable being used in lib/splunktaucclib/legacy/util.py:138: os.environ.
237Environment variable being used in lib/solnlib/splunkenv.py:237: os.environ.get.
199Environment variable being used in lib/solnlib/splunkenv.py:199: os.environ.
34Environment variable being used in bin/cribl.py:34: os.environ.
90Environment variable being used in lib/splunktaucclib/legacy/util.py:90: os.environ.
110Environment variable being used in lib/splunktaucclib/rest_handler/util.py:110: os.environ.
93Environment variable being used in lib/splunktaucclib/legacy/util.py:93: os.environ.
151Environment variable being used in lib/splunktaucclib/splunk_aoblib/setup_util.py:151: os.environ.get.
238Environment variable being used in lib/solnlib/splunkenv.py:238: os.environ.
149Environment variable being used in lib/splunktaucclib/splunk_aoblib/setup_util.py:149: os.environ.get.
78Environment variable being used in lib/splunktaucclib/rest_handler/admin_external.py:78: os.environ.
74Environment variable being used in lib/splunktaucclib/rest_handler/admin_external.py:74: os.environ.get.
75Environment variable being used in lib/splunktaucclib/rest_handler/admin_external.py:75: os.environ.
627Possible insecure HTTP Connection. Match: requests.post Positional arguments, ["?"]; Keyword arguments, {"headers": "?", "json": "?", "verify": "?"}
130Possible insecure HTTP Connection. Match: requests.Session.post Positional arguments, ["?"]; Keyword arguments, {"verify": "?", "data": "?"}
318Possible insecure HTTP Connection. Match: requests.get Positional arguments, ["?"]; Keyword arguments, {"headers": "?", "verify": "?"}
61Possible insecure HTTP Connection. Match: requests.request Positional arguments, []; Keyword arguments, {"method": "GET", "url": "?", "data": "?", "headers": "?", "timeout": "?", "verify": "?"}
252Possible insecure HTTP Connection. Match: requests.Session.get Positional arguments, ["rbac_roles"]; Keyword arguments, {}
590Possible insecure HTTP Connection. Match: requests.get Positional arguments, ["?"]; Keyword arguments, {"headers": "?", "verify": "?"}
153Possible insecure HTTP Connection. Match: requests.Session.request Positional arguments, ["?", "?"]; Keyword arguments, {"data": "?", "headers": "?", "stream": "?", "verify": "?", "proxies": "?", "cert": "?", "null": "?"}
607Possible insecure HTTP Connection. Match: requests.get Positional arguments, ["?"]; Keyword arguments, {"headers": "?", "verify": "?"}
282Possible insecure HTTP Connection. Match: requests.get Positional arguments, ["cribl_token"]; Keyword arguments, {}
175Possible insecure HTTP Connection. Match: requests.post Positional arguments, ["/api/v1/auth/login"]; Keyword arguments, {"json": "?", "verify": "?", "headers": "?"}
183Possible insecure HTTP Connection. Match: requests.post Positional arguments, ["/api/v1/auth/login"]; Keyword arguments, {"json": "?", "verify": "?", "headers": "?"}
282Possible insecure HTTP Connection. Match: requests.Session.get Positional arguments, ["cribl_token"]; Keyword arguments, {}
286Possible insecure HTTP Connection. Match: requests.Session.get Positional arguments, ["cribl_ssl_verify", "?"]; Keyword arguments, {}
66Possible insecure HTTP Connection. Match: requests.Session.get Positional arguments, ["?"]; Keyword arguments, {"verify": "?"}
651Possible insecure HTTP Connection. Match: requests.get Positional arguments, ["?"]; Keyword arguments, {"headers": "?", "verify": "?"}
32Possible insecure HTTP Connection. Match: requests.post Positional arguments, ["?"]; Keyword arguments, {"headers": "?", "data": "?", "verify": "?"}
66Possible insecure HTTP Connection. Match: requests.get Positional arguments, ["?"]; Keyword arguments, {"verify": "?"}
167Possible insecure HTTP Connection. Match: requests.post Positional arguments, ["/api/v1/auth/login"]; Keyword arguments, {"json": "?", "verify": "?", "headers": "?"}
634Possible insecure HTTP Connection. Match: requests.get Positional arguments, ["?"]; Keyword arguments, {"headers": "?", "verify": "?"}
287Possible insecure HTTP Connection. Match: requests.Session.get Positional arguments, ["cribl_ssl_certificate_path", "?"]; Keyword arguments, {}
681Possible insecure HTTP Connection. Match: requests.post Positional arguments, ["?"]; Keyword arguments, {"headers": "?", "json": "?", "verify": "?"}
327Possible insecure HTTP Connection. Match: requests.delete Positional arguments, ["?"]; Keyword arguments, {"headers": "?", "data": "?", "verify": "?"}
286Possible insecure HTTP Connection. Match: requests.get Positional arguments, ["cribl_ssl_verify", "?"]; Keyword arguments, {}
130Possible insecure HTTP Connection. Match: requests.post Positional arguments, ["?"]; Keyword arguments, {"verify": "?", "data": "?"}
58Possible insecure HTTP Connection. Match: requests.request Positional arguments, []; Keyword arguments, {"method": "GET", "url": "?", "data": "?", "headers": "?", "timeout": "?", "verify": "?"}
322Possible insecure HTTP Connection. Match: requests.post Positional arguments, ["?"]; Keyword arguments, {"headers": "?", "data": "?", "verify": "?"}
252Possible insecure HTTP Connection. Match: requests.get Positional arguments, ["rbac_roles"]; Keyword arguments, {}
153Possible insecure HTTP Connection. Match: requests.request Positional arguments, ["?", "?"]; Keyword arguments, {"data": "?", "headers": "?", "stream": "?", "verify": "?", "proxies": "?", "cert": "?", "null": "?"}
287Possible insecure HTTP Connection. Match: requests.get Positional arguments, ["cribl_ssl_certificate_path", "?"]; Keyword arguments, {}
34The following line will be inspected during code review.Possible secret disclosure found. Match: passSystemAuth = true
2The following line will be inspected during code review. Possible secret disclosure found. Match: AKIAqgCyALoAYABoAGAA
58Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
634Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
590Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
322Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
607Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
32Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
651Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
61Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
627Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
153Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
681Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
167Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
318Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
175Ensure that the SSL certificate validation for communications with outside the Splunk Cloud stack is enabled. This can be done by specifying the relevant parameters (verify, cafile etc) to True or the certificate path.
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
Suppressed 61 manual_check messages
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review:
The executable will be inspected during code review: