Skip to content

Conversation

@Regzox
Copy link
Contributor

@Regzox Regzox commented Oct 27, 2025

No description provided.

@Regzox Regzox self-assigned this Oct 27, 2025
@Regzox Regzox added the bug Something isn't working label Oct 27, 2025
@Regzox Regzox added this to the IT 160 milestone Oct 27, 2025
@GiooDev GiooDev requested a review from Salimdev October 27, 2025 10:58
@vitam-prg
Copy link
Collaborator

vitam-prg commented Oct 27, 2025

Logo
Checkmarx One – Scan Summary & Detailsfd406d67-047e-4bc9-806a-8f76d3a5829f

New Issues (198)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH Missing User Instruction /Dockerfile: 11
detailsA user should be specified in the dockerfile, otherwise the image will run as root
ID: c%2B6rSBVT%2FB1WJIexYVgRFkJK0UY%3D
HIGH Missing User Instruction /Dockerfile: 10
detailsA user should be specified in the dockerfile, otherwise the image will run as root
ID: h1npK6xb2c%2BVpTGfYSH%2BWUE%2BTl4%3D
HIGH Missing User Instruction /Dockerfile: 10
detailsA user should be specified in the dockerfile, otherwise the image will run as root
ID: gs5F2b2Ty7gJO9BLg2QFP5Cr1aU%3D
HIGH No New Privileges Not Set /vitam-dev.yml: 19
detailsEnsuring the process does not gain any new privileges lessens the risk associated with many operations.
ID: 3MHIh7nTyLmb1EmnpD9WTGGCeWM%3D
HIGH No New Privileges Not Set /vitam-recette.yml: 17
detailsEnsuring the process does not gain any new privileges lessens the risk associated with many operations.
ID: TVqUUGKvwYzeFyr9xHZs2WWF0%2Bc%3D
HIGH No New Privileges Not Set /vitam-recette.yml: 54
detailsEnsuring the process does not gain any new privileges lessens the risk associated with many operations.
ID: 3FeGJojshToJDRaMtUIMgwam3EA%3D
HIGH No New Privileges Not Set /docker-compose.yml: 10
detailsEnsuring the process does not gain any new privileges lessens the risk associated with many operations.
ID: NwHNYLkmunaYd2MuG7YLfzYKM%2B0%3D
HIGH Passwords And Secrets - Generic Password /vitamui_vars.yml: 210
detailsQuery to find passwords and secrets in infrastructure code.
ID: yo06VAd4Zu%2FnmYaelM7S%2Fvpu0mo%3D
HIGH Passwords And Secrets - Generic Password /docker-compose.yml: 18
detailsQuery to find passwords and secrets in infrastructure code.
ID: L5Vpbmh4twhpjcMpF69NVxCYPIM%3D
HIGH Passwords And Secrets - Generic Password /docker-compose.yml: 26
detailsQuery to find passwords and secrets in infrastructure code.
ID: kyGUOaeVg1WggQW6SwtExTE9hmo%3D
HIGH Passwords And Secrets - Generic Password /docker-compose.yml: 50
detailsQuery to find passwords and secrets in infrastructure code.
ID: zbxBnbqdpcn2mXH%2BF%2FqxbDd1cPY%3D
HIGH Passwords And Secrets - Generic Password /mongo_dev.yml: 37
detailsQuery to find passwords and secrets in infrastructure code.
ID: H4qV9cZz3IoWaVkFggojlRCqRNM%3D
HIGH Passwords And Secrets - Generic Password /mongo_cluster.yml: 34
detailsQuery to find passwords and secrets in infrastructure code.
ID: w%2BTMIhbh4BS6fkaJysHs%2FI6ecsE%3D
HIGH Passwords And Secrets - Generic Password /docker-compose.yml: 53
detailsQuery to find passwords and secrets in infrastructure code.
ID: lkoXRZNaVVfiwmLqMt8JEPLRo%2BQ%3D
HIGH Passwords And Secrets - Generic Password /mongo_cluster.yml: 55
detailsQuery to find passwords and secrets in infrastructure code.
ID: k3POaoAjqqVjc6MMdIDjx9AZYEI%3D
HIGH Passwords And Secrets - Generic Password /mongo_cluster.yml: 11
detailsQuery to find passwords and secrets in infrastructure code.
ID: X4h%2FfJdL1vM%2FlbykCuj6fyEURRo%3D
HIGH Passwords And Secrets - Generic Password /docker-compose.yml: 20
detailsQuery to find passwords and secrets in infrastructure code.
ID: lUbFg3EeTPMozdJxQOZ4iIpWVVw%3D
HIGH Passwords And Secrets - Generic Token /infra.yml: 25
detailsQuery to find passwords and secrets in infrastructure code.
ID: uTPxeYzGlONSJI34gAMuv3AzmuY%3D
HIGH Passwords And Secrets - Password in URL /mongo_dev.yml: 38
detailsQuery to find passwords and secrets in infrastructure code.
ID: QX%2FlWW265tWcWuI%2B%2Fyq8c26auCQ%3D
HIGH Privileged Containers Enabled /vitam-recette.yml: 14
detailsPrivileged containers should be used with extreme caution, they have all of the capabilities that the linux kernel offers for docker.
ID: PL7y7qF15hf4up%2F75Rp3jEDCm4Y%3D
HIGH Privileged Containers Enabled /docker-compose.yml: 21
detailsPrivileged containers should be used with extreme caution, they have all of the capabilities that the linux kernel offers for docker.
ID: OG4Z8xsOyvkZ75OzGPPCFU7%2BOYs%3D
HIGH Privileged Containers Enabled /docker-compose.yml: 52
detailsPrivileged containers should be used with extreme caution, they have all of the capabilities that the linux kernel offers for docker.
ID: gGoyT2KMpnwUgVjzbVhbh770BxE%3D
HIGH Privileged Containers Enabled /vitam-recette.yml: 51
detailsPrivileged containers should be used with extreme caution, they have all of the capabilities that the linux kernel offers for docker.
ID: CRfUFuYLAbZh9u0wv7lZwMNw5E4%3D
HIGH Privileged Containers Enabled /docker-compose.yml: 7
detailsPrivileged containers should be used with extreme caution, they have all of the capabilities that the linux kernel offers for docker.
ID: XD%2FDul6AN5Xiw3HTZjVlBTd9hHg%3D
HIGH Privileged Containers Enabled /vitam-dev.yml: 16
detailsPrivileged containers should be used with extreme caution, they have all of the capabilities that the linux kernel offers for docker.
ID: TeReFkIs1Dpmz6BIgH8HQNjO5zU%3D
HIGH Volume Has Sensitive Host Directory /docker-compose.yml: 26
detailsContainer has sensitive host directory mounted as a volume
ID: f%2BqL%2FuIiQbiOdYkmnW2NL5NbXXs%3D
HIGH Volume Has Sensitive Host Directory /vitam-recette.yml: 57
detailsContainer has sensitive host directory mounted as a volume
ID: zFzR%2Bt4AabGkXFkWz9JummlwqMM%3D
HIGH Volume Has Sensitive Host Directory /vitam-dev.yml: 26
detailsContainer has sensitive host directory mounted as a volume
ID: FcOp2XjFrsBBAM0RPN7ZPWBAyag%3D
HIGH Volume Has Sensitive Host Directory /docker-compose.yml: 25
detailsContainer has sensitive host directory mounted as a volume
ID: kJYs1lKAGlGg9inA5yZHUlrb%2Bqw%3D
HIGH Volume Has Sensitive Host Directory /vitam-recette.yml: 20
detailsContainer has sensitive host directory mounted as a volume
ID: PHYyuZrqhxIH9mzSN7Ee058OYZ0%3D
HIGH Volume Has Sensitive Host Directory /vitam-dev.yml: 27
detailsContainer has sensitive host directory mounted as a volume
ID: sEL98SF8HUhvwWQWCHExl7gmWyw%3D
HIGH Volume Has Sensitive Host Directory /vitam-dev.yml: 25
detailsContainer has sensitive host directory mounted as a volume
ID: 6QgaRDJqegY2uWlsaybpMrEOcFw%3D
MEDIUM Add Instead of Copy /Dockerfile: 46
detailsUsing ADD to load external installation scripts could lead to an evil web server leveraging this and loading a malicious script.
ID: 3z8KHK3w2z7TU7UO%2F%2FP6EJmQshw%3D
MEDIUM Add Instead of Copy /Dockerfile: 47
detailsUsing ADD to load external installation scripts could lead to an evil web server leveraging this and loading a malicious script.
ID: 1jzPkmtnWlnPBmJxWjRGXmfOvmk%3D
MEDIUM Add Instead of Copy /Dockerfile: 15
detailsUsing ADD to load external installation scripts could lead to an evil web server leveraging this and loading a malicious script.
ID: V%2FIQ52oY%2B3c5Lsrhfy97UzpVOQ4%3D
MEDIUM Container Capabilities Unrestricted /mongo_cluster.yml: 4
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: tWAihPzlZcrvrlzUA2JyMawFO%2BU%3D
MEDIUM Container Capabilities Unrestricted /docker-compose.yml: 4
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: %2FYujmJiY8aLFj6Io9ayQ4seL0Js%3D
MEDIUM Container Capabilities Unrestricted /mongo_cluster.yml: 27
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: 8sQ%2BWqMI3B6VAhNM6j7SWIrkSDw%3D
MEDIUM Container Capabilities Unrestricted /docker-compose.yml: 49
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: JTz8%2FCKukxdHmf8DMcT15oW5Cxk%3D
MEDIUM Container Capabilities Unrestricted /docker-compose.yml: 27
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: Oqwi6qij3fyL%2FU7F6xBPNGMnSXg%3D
MEDIUM Container Capabilities Unrestricted /vitam-dev.yml: 4
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: XPeDfEcuPtPPUVnJHeSNBmjBefw%3D
MEDIUM Container Capabilities Unrestricted /mongo_dev.yml: 25
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: 8b6RZ39wA%2BH%2FR5%2FhQNm6QGxYbkc%3D
MEDIUM Container Capabilities Unrestricted /jaeger-docker-compose.yml: 3
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: %2BU5kYv%2BQErfy2Ueuk7s9%2FPreTcA%3D
MEDIUM Container Capabilities Unrestricted /mongo_cluster.yml: 49
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: 5T%2B2yJ34YDEbuqZatH7StW2ROK0%3D
MEDIUM Container Capabilities Unrestricted /docker-compose.yml: 41
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: vKRi6%2Brt5NXeShgpuRmvDMuOu%2FE%3D
MEDIUM Container Capabilities Unrestricted /docker-compose.yml: 4
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: wvwcNOI0MA%2FmQEdsf%2FIo32rBiUg%3D
MEDIUM Container Capabilities Unrestricted /docker-compose.yml: 41
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: nEXRJd6sDjQz7dxFUKtEozLPDho%3D
MEDIUM Container Capabilities Unrestricted /vitam-dev.yml: 17
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: CtewUYcoFCCtcsJRYZ%2FWUHYYsis%3D
MEDIUM Container Capabilities Unrestricted /docker-compose.yml: 2
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: 5EvNdeLlE9o1UgyLGl8grZRLMJ8%3D
MEDIUM Container Capabilities Unrestricted /docker-compose.yml: 17
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: 8ZND6aa8SaFwF4Y0ySdriljFAQU%3D
MEDIUM Container Capabilities Unrestricted /docker-compose.yml: 4
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: bzJsA%2BNleWrzBU49RA%2FzfwvF5Bk%3D
MEDIUM Container Capabilities Unrestricted /mongo_dev.yml: 4
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: HAQMcqo3NxSH53uY9%2F86j1DxKkg%3D
MEDIUM Container Capabilities Unrestricted /docker-compose.yml: 3
detailsSome capabilities are not needed in certain (or any) containers. Make sure that you only add capabilities that your container needs. Drop unnec...
ID: Dx7DNjrUEInOg5lggGIqN1DhMgU%3D
MEDIUM Container Traffic Not Bound To Host Interface /docker-compose.yml: 7
detailsIncoming container traffic should be bound to a specific host interface
ID: vBzRVymZcLp%2B9KQNej6xKzJ8gq0%3D
MEDIUM Container Traffic Not Bound To Host Interface /vitam-recette.yml: 58
detailsIncoming container traffic should be bound to a specific host interface
ID: JASnYkKmZZwgE0Xmq55s2ha5WcA%3D
MEDIUM Container Traffic Not Bound To Host Interface /mongo_dev.yml: 29
detailsIncoming container traffic should be bound to a specific host interface
ID: VfRkgAiXXtoV37h1OWoor2e52WQ%3D
MEDIUM Container Traffic Not Bound To Host Interface /docker-compose.yml: 19
detailsIncoming container traffic should be bound to a specific host interface
ID: rNTMIH%2B%2FGObwK6TG58IIF%2FULVs0%3D
MEDIUM Container Traffic Not Bound To Host Interface /docker-compose.yml: 38
detailsIncoming container traffic should be bound to a specific host interface
ID: QArV%2FYMVEnUk5%2BPMAeeWeXcCHRM%3D
MEDIUM Container Traffic Not Bound To Host Interface /mongo_dev.yml: 12
detailsIncoming container traffic should be bound to a specific host interface
ID: FbwF07ssotu7VNkx2bRJOo6i3Gc%3D
MEDIUM Container Traffic Not Bound To Host Interface /jaeger-docker-compose.yml: 5
detailsIncoming container traffic should be bound to a specific host interface
ID: ZXTpkT3Q2U9w9goISURYgyX%2F5uc%3D
MEDIUM Container Traffic Not Bound To Host Interface /docker-compose.yml: 47
detailsIncoming container traffic should be bound to a specific host interface
ID: 2Ibgo0iFOXxfGXmu%2B7PJ7JmcPq4%3D
MEDIUM Container Traffic Not Bound To Host Interface /docker-compose.yml: 14
detailsIncoming container traffic should be bound to a specific host interface
ID: tLrWzwXByJ1vgnVhzH0VpCKJGPc%3D
MEDIUM Container Traffic Not Bound To Host Interface /vitam-recette.yml: 21
detailsIncoming container traffic should be bound to a specific host interface
ID: HR%2BVDKfzUiASex3jvkto4wnXnfE%3D
MEDIUM Container Traffic Not Bound To Host Interface /vitam-dev.yml: 28
detailsIncoming container traffic should be bound to a specific host interface
ID: lnDrwZ%2Bn5j8Uy%2B4JMcbfSlaXNSk%3D
MEDIUM Healthcheck Not Set /mongo_cluster.yml: 27
detailsCheck containers periodically to see if they are running properly.
ID: MGfbNYY62B3Xc5IXRs4qwM2DE8g%3D
MEDIUM Healthcheck Not Set /docker-compose.yml: 4
detailsCheck containers periodically to see if they are running properly.
ID: c8ovE%2BtMKXN2m%2Bvpl7D5OhN1Fp8%3D
MEDIUM Healthcheck Not Set /vitam-dev.yml: 4
detailsCheck containers periodically to see if they are running properly.
ID: pDj2c5I0UqB7kCbTV6vDe9OEcEw%3D
MEDIUM Healthcheck Not Set /mongo_cluster.yml: 4
detailsCheck containers periodically to see if they are running properly.
ID: 1OE%2B5MtyXGLDueFlzVkl86yf25Q%3D
MEDIUM Healthcheck Not Set /vitam-recette.yml: 41
detailsCheck containers periodically to see if they are running properly.
ID: zWli4ItNWDrXryV2m2RwHdQ2RQo%3D
MEDIUM Healthcheck Not Set /jaeger-docker-compose.yml: 3
detailsCheck containers periodically to see if they are running properly.
ID: ewtOohpELOVZsEA0VN78mVV7UUA%3D
MEDIUM Healthcheck Not Set /mongo_dev.yml: 25
detailsCheck containers periodically to see if they are running properly.
ID: UKdkSxg75l22yErk7zzD9XUIzOo%3D

More results are available on the CxOne platform

Fixed Issues (41) Great job! The following issues were fixed in this Pull Request
Severity Issue Source File / Package
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 213
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 212
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 213
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 213
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 279
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 228
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 245
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 279
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 228
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 262
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 245
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 280
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 279
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 246
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 245
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 229
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 228
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 262
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 263
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 262
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 171
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 315
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 305
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 190
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 170
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 189
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 190
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 191
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 305
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 95
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 171
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 295
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 96
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 128
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 127
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 95
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 156
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 97
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 192
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 190
LOW Log_Forging /api/api-collect/collect/src/main/java/fr/gouv/vitamui/collect/server/rest/ProjectController.java: 171

Use @Checkmarx to reach out to us for assistance.

Just send a PR comment with @Checkmarx followed by a natural language request.

Examples: @Checkmarx how are you able to help me? @Checkmarx rescan this PR

@Regzox Regzox marked this pull request as draft October 27, 2025 11:25
@Regzox Regzox marked this pull request as ready for review October 27, 2025 11:35
@Regzox Regzox merged commit 75f1481 into develop Oct 27, 2025
12 checks passed
@Regzox Regzox deleted the bugs_15339 branch October 27, 2025 13:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants