Apereo CAS - Identity & Single Sign On for all earthlings and beyond.
380 matches across 10 categories. Click a row to expand file-level details.
| Severity | File | Line | Snippet |
|---|---|---|---|
| CRITICAL | …s/web/support/gen/CookieRetrievingCookieGenerator.java | 109 | var cookie = org.springframework.web.util.WebUtils.getCookie(request, Objects.requireNonNull(getCookieName() |
| CRITICAL | …cenarios/sso-access-per-service/services/Sample-2.json | 15 | "randomNumber" : "groovy { return org.apereo.cas.util.RandomUtils.generateSecureRandomId() }" |
| CRITICAL | …cenarios/sso-access-per-service/services/Sample-1.json | 15 | "randomNumber" : "groovy { return org.apereo.cas.util.RandomUtils.generateSecureRandomId() }" |
| CRITICAL | …er-documentation/installation/Troubleshooting-Guide.md | 166 | at com.sun.net.ssl.internal.ssl.Alerts.getSSLException(Unknown Source) |
| CRITICAL | …er-documentation/installation/Troubleshooting-Guide.md | 167 | at com.sun.net.ssl.internal.ssl.SSLSocketImpl.fatal(Unknown Source) |
| CRITICAL | …er-documentation/installation/Troubleshooting-Guide.md | 168 | at com.sun.net.ssl.internal.ssl.Handshaker.fatalSE(Unknown Source) |
| CRITICAL | …er-documentation/installation/Troubleshooting-Guide.md | 169 | at com.sun.net.ssl.internal.ssl.Handshaker.fatalSE(Unknown Source) |
| CRITICAL | …er-documentation/installation/Troubleshooting-Guide.md | 170 | at com.sun.net.ssl.internal.ssl.ClientHandshaker.serverCertificate(Unknown Source) |
| CRITICAL | …er-documentation/installation/Troubleshooting-Guide.md | 201 | org.apereo.cas.client.validation.Saml11TicketValidator.retrieveResponseFromServer(Saml11TicketValidator.java:203) |
| CRITICAL | …er-documentation/installation/Troubleshooting-Guide.md | 202 | org.apereo.cas.client.validation.AbstractUrlBasedTicketValidator.validate(AbstractUrlBasedTicketValidator.java:185) |
| CRITICAL | …-documentation/authentication/SPNEGO-Authentication.md | 234 | at sun.security.jgss.krb5.Krb5Context.acceptSecContext(Unknown Source) |
| CRITICAL | …org/apereo/cas/config/CasJpaUtilAutoConfiguration.java | 52 | com.mysql.cj.jdbc.Driver.class.getName(), |
| CRITICAL | …org/apereo/cas/config/CasJpaUtilAutoConfiguration.java | 55 | org.mariadb.jdbc.Driver.class.getName() |
| CRITICAL | …ereo/cas/heimdall/HeimdallAuthorizationController.java | 59 | requestBody = @io.swagger.v3.oas.annotations.parameters.RequestBody( |
| CRITICAL | …ereo/cas/heimdall/HeimdallAuthorizationController.java | 98 | requestBody = @io.swagger.v3.oas.annotations.parameters.RequestBody( |
| CRITICAL | …/org/apereo/cas/config/CasJaversAutoConfiguration.java | 100 | @Pointcut("execution(* org.apereo.cas.services.ServicesManager.save(..))") |
| CRITICAL | …meleaf/src/main/resources/static/js/palantir-system.js | 153 | const originalLabels = Chart.defaults.plugins.legend.labels.generateLabels(chart); |
| CRITICAL | …hymeleaf/src/main/resources/static/js/inwebo/client.js | 3 | o=(h[2]||"").split(".").sort(),n){for(l=oa.event.special[n]||{},m=i[n=(d?l.delegateType:l.bindType)||n]||[],h=h[ |
| CRITICAL | …hymeleaf/src/main/resources/static/js/inwebo/client.js | 4 | if(v="abort",r.add(n.complete),w.done(n.success),w.fail(n.error),d=Y(Kb,n,b,w)){if(w.readyState=1,k&&p.trigger(" |
| CRITICAL | …hymeleaf/src/main/resources/static/js/inwebo/client.js | 5 | this.options.axis&&"x"===this.options.axis||(this.helper[0].style.top=this.position.top+"px"),a.ui.ddmanager&&a.ui.d |
| CRITICAL | …c/main/resources/templates/consent/casConsentView.html | 171 | #{screen.consent.options.desc.attributevalue.first(${service.id})} + |
| CRITICAL | …c/main/resources/templates/consent/casConsentView.html | 173 | #{screen.consent.options.desc.attributevalue.second(${service.id})} + |
| CRITICAL | …c/main/resources/templates/consent/casConsentView.html | 175 | #{screen.consent.options.desc.attributevalue.third(${service.id})} + |
| CRITICAL | …apereo/cas/support/rest/RegisteredServiceResource.java | 72 | requestBody = @io.swagger.v3.oas.annotations.parameters.RequestBody( |
| CRITICAL | …/cas/config/CasJpaTicketRegistryAutoConfiguration.java | 231 | val repo = new org.springframework.integration.jdbc.lock.DefaultLockRepository(dataSourceTicket); |
| CRITICAL | …g/OidcDynamicClientRegistrationEndpointController.java | 61 | requestBody = @io.swagger.v3.oas.annotations.parameters.RequestBody( |
| CRITICAL | …dynareg/OidcClientConfigurationEndpointController.java | 94 | requestBody = @io.swagger.v3.oas.annotations.parameters.RequestBody( |
| CRITICAL | …llers/jwks/OidcJwksRegistrationEndpointController.java | 68 | requestBody = @io.swagger.v3.oas.annotations.parameters.RequestBody( |
| CRITICAL | …IdPDelegatedClientAuthenticationRequestCustomizer.java | 136 | if (org.apache.commons.lang3.StringUtils.isBlank(identityProviderEntityId)) { |
| CRITICAL | …dp/metadata/SamlRegisteredServiceMetadataEndpoint.java | 216 | requestBody = @io.swagger.v3.oas.annotations.parameters.RequestBody(required = true, |
| CRITICAL | …va/org/apereo/cas/webauthn/web/WebAuthnController.java | 106 | requestBody = @io.swagger.v3.oas.annotations.parameters.RequestBody( |
| CRITICAL | …shell/commands/util/ValidateLdapConnectionCommand.java | 131 | if (org.apache.commons.lang3.StringUtils.isNotBlank(userPassword)) { |
| CRITICAL | …thn/web/flow/WebAuthnMultifactorWebflowConfigurer.java | 97 | val appId = org.apache.commons.lang3.StringUtils.defaultIfBlank(webAuthn.getCore().getApplicationId(), casPr |
| CRITICAL | …dpoints/OAuth20AccessTokenEndpointControllerTests.java | 681 | assertEquals(org.springframework.http.HttpStatus.FOUND.value(), devResponse.getStatus()); |
| CRITICAL | …/cas/adaptors/duo/web/DuoSecurityAdminApiEndpoint.java | 129 | @io.swagger.v3.oas.annotations.parameters.RequestBody( |
| CRITICAL | …eo/cas/config/CasSpringBootAdminAutoConfiguration.java | 95 | val nettyHttpClient = reactor.netty.http.client.HttpClient.create() |
| CRITICAL | …in/java/org/apereo/cas/logging/CloudWatchAppender.java | 104 | org.apereo.cas.util.LoggingUtils.error(LOGGER, e); |
| CRITICAL | …in/java/org/apereo/cas/logging/CloudWatchAppender.java | 226 | org.apereo.cas.util.LoggingUtils.error(LOGGER, e); |
| CRITICAL | …in/java/org/apereo/cas/logging/CloudWatchAppender.java | 234 | org.apereo.cas.util.LoggingUtils.error(LOGGER, e); |
| CRITICAL | …in/java/org/apereo/cas/logging/CloudWatchAppender.java | 261 | org.apereo.cas.util.LoggingUtils.error(LOGGER, e); |
| CRITICAL | …in/java/org/apereo/cas/logging/CloudWatchAppender.java | 303 | org.apereo.cas.util.LoggingUtils.error(LOGGER, e); |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …s/throttle/DefaultThrottledRequestResponseHandler.java | 22 | public class DefaultThrottledRequestResponseHandler implements ThrottledRequestResponseHandler { |
| LOW | ci/tests/puppeteer/run.sh | 55 | function downloadAndRunExternalTomcat() { |
| LOW | …scenarios/redis-ticket-registry-idle-timeout/script.js | 9 | async function verifyTicketGrantingTicketCount(count = 0) { |
| LOW | …/scenarios/passwordless-login-user-selection/script.js | 29 | async function authenticateWithDelegation(browser) { |
| LOW | …/scenarios/passwordless-login-user-selection/script.js | 53 | async function authenticateWithPasswordlessToken(browser) { |
| LOW | …tests/puppeteer/scenarios/pm-account-profile/script.js | 15 | async function importMultifactorTrustedRecord() { |
| LOW | …tests/puppeteer/scenarios/pm-account-profile/script.js | 50 | async function removeMultifactorTrustedRecord(record) { |
| LOW | …tests/puppeteer/scenarios/pm-account-profile/script.js | 54 | async function verifyAccountManagementFlow(browser) { |
| LOW | …tests/puppeteer/scenarios/pm-account-profile/script.js | 131 | async function verifyPasswordManagementFlow(browser) { |
| LOW | …ppeteer/scenarios/pm-mfa-device-registration/script.js | 6 | async function registerGoogleAuthenticatorAccount() { |
| LOW | …ppeteer/scenarios/pm-mfa-device-registration/script.js | 17 | async function deleteGoogleAuthenticatorAccounts() { |
| LOW | …ppeteer/scenarios/pm-mfa-device-registration/script.js | 21 | async function passwordResetFlowMfaWithoutRegisteredDevice(browser) { |
| LOW | …sts/puppeteer/scenarios/oidc-authzcode-login/script.js | 4 | async function verifyAccessTokenIsLimited(context) { |
| LOW | …sts/puppeteer/scenarios/oidc-authzcode-login/script.js | 43 | async function verifyAccessTokenIsNeverReceived(context) { |
| LOW | …sts/puppeteer/scenarios/oidc-authzcode-login/script.js | 75 | async function verifyAccessTokenAndProfile(context) { |
| LOW | …sts/puppeteer/scenarios/oidc-authzcode-login/script.js | 183 | async function verifyMissingTicketGrantingCookie(context) { |
| LOW | …ts/puppeteer/scenarios/delegated-login-saml2/script.js | 8 | async function verifyNormalAuthenticationFlow(browser) { |
| LOW | …/tests/puppeteer/scenarios/oidc-login-jwt-at/script.js | 62 | async function verifyAccessTokenWithProfile(accessToken) { |
| LOW | …r/scenarios/shibboleth-idp-service-selection/script.js | 4 | function getShibbolethUrlForEntityId(entityId) { |
| LOW | …uppeteer/scenarios/surrogate-login-selection/script.js | 20 | async function verifyImpersonationByPrincipalAttributes(browser) { |
| LOW | …uppeteer/scenarios/surrogate-login-selection/script.js | 39 | async function verifyImpersonationByPrincipalAttributesDisabled(browser) { |
| LOW | …narios/mfa-duo-universal-login-storage-fails/script.js | 3 | async function makeBrowserStorageUnavailable(page) { |
| LOW | …ests/puppeteer/scenarios/oidc-token-exchange/script.js | 97 | async function verifyTokenExchangeNativeSso() { |
| LOW | …eer/scenarios/mfa-webauthn-register-qr-login/script.js | 7 | async function verifyFlowUsingQRCodeButtonSameWindow() { |
| LOW | …uppeteer/scenarios/account-mgmt-registration/script.js | 4 | async function verifyAccountRegistrationWithOidcService() { |
| LOW | …uppeteer/scenarios/account-mgmt-registration/script.js | 30 | async function submitAccountRegistrationRequest(page, browser) { |
| LOW | …uppeteer/scenarios/account-mgmt-registration/script.js | 70 | async function verifyAccountRegistrationWithCasService() { |
| LOW | …enarios/pm-account-profile-mfa-trusteddevice/script.js | 7 | async function passwordResetFlowWithoutTrustedDevice(browser) { |
| LOW | …enarios/pm-account-profile-mfa-trusteddevice/script.js | 58 | async function passwordResetFlowWithTrustedDevice(browser) { |
| LOW | …enarios/pm-account-profile-mfa-trusteddevice/script.js | 97 | async function passwordResetFlowWithAccountProfileWithoutTrustedDevice(browser) { |
| LOW | …enarios/pm-account-profile-mfa-trusteddevice/script.js | 129 | async function passwordResetFlowWithAccountProfileWithTrustedDeviceIgnored(browser) { |
| LOW | …scenarios/redis-ticket-registry-loadbalanced/script.js | 5 | async function ensureNoSsoSessionsExistAfterLogout(page, port) { |
| LOW | …scenarios/redis-ticket-registry-loadbalanced/script.js | 38 | async function checkTicketValidationAcrossNodes(browser) { |
| LOW | …/scenarios/passwordless-delegation-with-ldap/script.js | 5 | async function verifyDelegatedAuthenticationFlow(page) { |
| LOW | …/scenarios/passwordless-delegation-with-ldap/script.js | 21 | async function verifyPasswordRequestFlow(page) { |
| LOW | …puppeteer/scenarios/surrogate-oidc-authzcode/script.js | 4 | async function verifyImpersonationAutoSelected(browser) { |
| LOW | …puppeteer/scenarios/surrogate-oidc-authzcode/script.js | 69 | async function verifyImpersonationUserChoice(browser) { |
| LOW | …er/scenarios/mfa-gauth-login-trusted-devices/script.js | 4 | async function loginAndRegisterTrustedDevice(browser) { |
| LOW | …er/scenarios/mfa-gauth-login-trusted-devices/script.js | 30 | async function loginFromPublicWorkstation(browser) { |
| LOW | …puppeteer/scenarios/oidc-par-authzcode-login/script.js | 4 | async function sendPushAuthorizationRequest(redirectUrl) { |
| LOW | …puppeteer/scenarios/oidc-par-authzcode-login/script.js | 24 | async function verifyPushAuthorizationRequestSuccess() { |
| LOW | …puppeteer/scenarios/oidc-par-authzcode-login/script.js | 92 | async function verifyPushAuthorizationFailure() { |
| LOW | …s/puppeteer/scenarios/oidc-clientcredentials/script.js | 63 | async function verifyClientCredentialsGrantType() { |
| LOW | …puppeteer/scenarios/interrupt-aftersso-login/script.js | 42 | async function verifyInterruptionBlocked(context) { |
| LOW | …gate-login-selection-duomfa-universal-prompt/script.js | 7 | async function verifyImpersonationWithMfa(page) { |
| LOW | …gate-login-selection-duomfa-universal-prompt/script.js | 45 | async function verifyNoImpersonationWithMfa(page) { |
| LOW | ci/tests/puppeteer/scenarios/oidc-logout/script.js | 4 | async function verifyLogoutWithIdTokenHint(clientId, casService, page) { |
| LOW | ci/docs/publish.sh | 18 | function validateProjectDocumentation() { |
| LOW | docs/cas-server-documentation/javascripts/main.js | 3 | function isDocumentationSiteViewedLocally() { |
| LOW | docs/cas-server-documentation/javascripts/main.js | 7 | function generateNavigationBarAndCrumbs() { |
| LOW | docs/cas-server-documentation/javascripts/main.js | 31 | function getActiveDocumentationVersionInView(returnBlankIfNoVersion) { |
| LOW | docs/cas-server-documentation/javascripts/main.js | 53 | function loadSidebarForActiveVersion() { |
| LOW | docs/cas-server-documentation/javascripts/main.js | 166 | function generateSidebarLinksForActiveVersion() { |
| LOW | …thymeleaf/src/main/resources/static/js/palantir-mfa.js | 1 | async function populateMultifactorProviderTables() { |
| LOW | …thymeleaf/src/main/resources/static/js/palantir-mfa.js | 99 | async function initializeMultifactorOperations() { |
| LOW | …thymeleaf/src/main/resources/static/js/palantir-mfa.js | 204 | async function initializeTrustedMultifactorOperations() { |
| LOW | …ymeleaf/src/main/resources/static/js/palantir-authz.js | 1 | async function initializeHeimdallOperations() { |
| LOW | …ymeleaf/src/main/resources/static/js/palantir-authz.js | 101 | async function initializeAccessStrategyOperations() { |
| LOW | …eleaf/src/main/resources/static/js/palantir-consent.js | 1 | async function initializeConsentOperations() { |
| LOW | …thymeleaf/src/main/resources/static/js/palantir-sso.js | 29 | async function initializeSsoSessionOperations() { |
| 130 more matches not shown… | |||
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …eteer/scenarios/oidc-login-strapi/strapi/entrypoint.sh | 1 | #!/bin/bash |
| LOW | ci/tests/elastic/apm-server.yml | 1 | ######################### APM Server Configuration ######################### |
| LOW | ci/tests/elastic/apm-server.yml | 21 | |
| LOW | ci/tests/elastic/apm-server.yml | 41 | #rate_limit: |
| LOW | ci/tests/elastic/apm-server.yml | 61 | |
| LOW | ci/tests/elastic/apm-server.yml | 81 | # request from the agent. |
| LOW | ci/tests/elastic/apm-server.yml | 101 | # Path to file containing the certificate for server authentication. |
| LOW | ci/tests/elastic/apm-server.yml | 121 | |
| LOW | ci/tests/elastic/apm-server.yml | 141 | |
| LOW | ci/tests/elastic/apm-server.yml | 161 | #source_mapping: |
| LOW | ci/tests/elastic/apm-server.yml | 181 | #elasticsearch: |
| LOW | ci/tests/elastic/apm-server.yml | 201 | # When using APM agent configuration, information fetched from Elasticsearch or Kibana will be cached in memory for |
| LOW | ci/tests/elastic/apm-server.yml | 221 | # Scheme and port can be left out and will be set to the default (`http` and `5601`). |
| LOW | ci/tests/elastic/apm-server.yml | 241 | # |
| LOW | ci/tests/elastic/apm-server.yml | 261 | #ssl.supported_protocols: [TLSv1.0, TLSv1.1, TLSv1.2] |
| LOW | ci/tests/elastic/apm-server.yml | 281 | |
| LOW | ci/tests/elastic/apm-server.yml | 301 | |
| LOW | ci/tests/elastic/apm-server.yml | 321 | #username: "elastic" |
| LOW | ci/tests/elastic/apm-server.yml | 341 | # tries to reconnect. If the attempt fails, the backoff timer is increased |
| LOW | ci/tests/elastic/apm-server.yml | 361 | # Enable custom SSL settings. Set to false to ignore custom SSL settings for secure communication. |
| LOW | ci/tests/elastic/apm-server.yml | 381 | #ssl.verification_mode: full |
| LOW | ci/tests/elastic/apm-server.yml | 401 | #ssl.cipher_suites: [] |
| LOW | ci/tests/elastic/apm-server.yml | 421 | # Configure escaping HTML symbols in strings. |
| LOW | ci/tests/elastic/apm-server.yml | 441 | # Optional maximum time to live for a connection to Logstash, after which the |
| LOW | ci/tests/elastic/apm-server.yml | 461 | # after a network error. After waiting backoff.init seconds, apm-server |
| LOW | ci/tests/elastic/apm-server.yml | 481 | # Enable SSL support. SSL is automatically enabled if any SSL setting is set. |
| LOW | ci/tests/elastic/apm-server.yml | 501 | #ssl.verification_mode: full |
| LOW | ci/tests/elastic/apm-server.yml | 521 | #ssl.cipher_suites: [] |
| LOW | ci/tests/elastic/apm-server.yml | 541 | # using any event field. To set the topic from document type use `%{[type]}`. |
| LOW | ci/tests/elastic/apm-server.yml | 561 | # Authentication details. Password is required if username is set. |
| LOW | ci/tests/elastic/apm-server.yml | 581 | #retry.max: 3 |
| LOW | ci/tests/elastic/apm-server.yml | 601 | |
| LOW | ci/tests/elastic/apm-server.yml | 621 | # Set the compression level. Currently only gzip provides a compression level |
| LOW | ci/tests/elastic/apm-server.yml | 641 | #ssl.enabled: false |
| LOW | ci/tests/elastic/apm-server.yml | 661 | |
| LOW | ci/tests/elastic/apm-server.yml | 681 | |
| LOW | ci/tests/elastic/apm-server.yml | 701 | # Name of the Kerberos user. It is used when auth_type is set to password. |
| LOW | ci/tests/elastic/apm-server.yml | 721 | # Hosts to report instrumentation results to. |
| LOW | ci/tests/elastic/apm-server.yml | 741 | |
| LOW | ci/tests/elastic/apm-server.yml | 761 | # Windows systems default to file output. All other systems default to syslog. |
| LOW | ci/tests/elastic/apm-server.yml | 781 | # The period after which to log the internal metrics. The default is 30s. |
| LOW | ci/tests/elastic/apm-server.yml | 801 | |
| LOW | ci/tests/elastic/apm-server.yml | 821 | #http.enabled: false |
| LOW | ci/tests/elastic/apm-server.yml | 841 | # output configuration. This means that if you have the Elasticsearch output configured, |
| LOW | ci/tests/elastic/apm-server.yml | 861 | |
| LOW | ci/tests/elastic/apm-server.yml | 881 | # The maximum number of seconds to wait before attempting to connect to |
| LOW | ci/tests/elastic/apm-server.yml | 901 | # * certificate, which verifies that the provided certificate is signed by a |
| LOW | ci/tests/elastic/apm-server.yml | 921 | #ssl.key: "/etc/pki/client/cert.key" |
| LOW | ci/tests/ldap/run-ad-server.sh | 1 | #!/bin/bash |
| LOW | ci/tests/cassandra/cassandra.yaml | 1 | |
| LOW | ci/tests/cassandra/cassandra.yaml | 21 | # Specifying initial_token will override this setting on the node's initial start, |
| LOW | ci/tests/cassandra/cassandra.yaml | 41 | |
| LOW | ci/tests/cassandra/cassandra.yaml | 61 | # this defines the maximum amount of time a dead host will have hints |
| LOW | ci/tests/cassandra/cassandra.yaml | 81 | |
| LOW | ci/tests/cassandra/cassandra.yaml | 101 | # Authentication backend, implementing IAuthenticator; used to identify users |
| LOW | ci/tests/cassandra/cassandra.yaml | 121 | # Part of the Authentication & Authorization backend, implementing IRoleManager; used |
| LOW | ci/tests/cassandra/cassandra.yaml | 141 | |
| LOW | ci/tests/cassandra/cassandra.yaml | 161 | # Will be disabled automatically for AllowAllAuthorizer. |
| LOW | ci/tests/cassandra/cassandra.yaml | 181 | credentials_validity_in_ms: 2000 |
| LOW | ci/tests/cassandra/cassandra.yaml | 201 | partitioner: org.apache.cassandra.dht.Murmur3Partitioner |
| 63 more matches not shown… | |||
| Severity | File | Line | Snippet |
|---|---|---|---|
| MEDIUM | ci/tests/elastic/apm-server.yml | 19 | # Define a shared secret token for authorizing agents using the "Bearer" authorization method. |
| MEDIUM | ci/tests/ldap/run-ldap-server.sh | 34 | # Create an empty OpenLdap server for the company Example Inc. and the domain example.org. |
| MEDIUM | ci/tests/cassandra/generate-keys.sh | 52 | # Create the cluster key for cluster communication. |
| MEDIUM | ci/tests/cassandra/generate-keys.sh | 57 | # Create the public key for the cluster which is used to identify nodes. |
| MEDIUM | ci/tests/cassandra/generate-keys.sh | 70 | # Create the client key for CQL. |
| MEDIUM | ci/tests/cassandra/generate-keys.sh | 75 | # Create the public key for the client to identify itself. |
| MEDIUM | ci/tests/cassandra/generate-keys.sh | 84 | # Create a pks12 keystore file |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | ci/tests/cassandra/cassandra.yaml | 1109 | # Step 1: Set internode_encryption=<dc|rack|all> and explicitly set optional=true. Restart all nodes |
| LOW | ci/tests/cassandra/cassandra.yaml | 1111 | # Step 2: Set optional=false (or remove it) and if you generated truststores and want to use mutual |
| LOW | ci/tests/cassandra/cassandra.yaml | 1156 | # Step 1: Set enabled=true and explicitly set optional=true. Restart all nodes |
| LOW | ci/tests/cassandra/cassandra.yaml | 1158 | # Step 2: Set optional=false (or remove it) and if you generated truststores and want to use mutual |
| LOW | gradle/libs.versions.toml | 272 | # This section handles Gradle build classpath dependency versions |
| LOW | gradle/libs.versions.toml | 808 | # This section handles Gradle build classpath dependencies |
| Severity | File | Line | Snippet |
|---|---|---|---|
| MEDIUM | ci/tests/cassandra/cassandra.yaml | 46 | # initial_token allows you to specify tokens manually. While you can use it with |
| MEDIUM | ci/tests/cassandra/cassandra.yaml | 715 | # you may want to adjust max_value_size_in_mb accordingly. This should be positive and less than 2048. |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | etc/loadtests/locust/cas/samlLocust.py | 3 | |
| LOW | etc/loadtests/locust/cas/allLocust.py | 1 | |
| LOW | etc/loadtests/locust/cas/casLocust.py | 3 | |
| LOW | etc/loadtests/locust/cas/casLocust.py | 10 |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | …web/flow/CasSimpleMultifactorSendTokenActionTests.java | 53 | "mail", List.of("cas@example.org", "user@example.com"), |
| LOW | …ain/resources/templates/login/casLoginMessageView.html | 16 | <span class="mdc-list-item__text" th:utext="${message.text}">Lorem ipsum dolor sit amet, consectetur |
| LOW | …ain/resources/templates/login/casLoginMessageView.html | 16 | <span class="mdc-list-item__text" th:utext="${message.text}">Lorem ipsum dolor sit amet, consectetur |
| LOW | …apereo/cas/support/saml/SamlAttributeEncoderTests.java | 23 | original.put("address", EncodingUtils.hexEncode("123 Main Street")); |
| Severity | File | Line | Snippet |
|---|---|---|---|
| LOW | ci/tests/elastic/apm-server.yml | 594 | # Set max_retries to a value less than 0 to retry |
| LOW | ci/tests/cassandra/generate-keys.sh | 23 | # Check if cluster-name and password are provided as params.... |
| Severity | File | Line | Snippet |
|---|---|---|---|
| MEDIUM | ci/tests/cassandra/cassandra.yaml | 1318 | # each write which may be lower in order to facilitate availability. |