concourse / concourse

Profiling endpoint automatically exposed on /debug/pprof

GO-S2108
Security
Major
5 months ago a year old
Seen in 1 file
1

Import blacklist: crypto/md5

GSC-G501
Security
Minor
5 months ago 4 years old
Seen in 6 files
6

Bind to all interfaces

GSC-G102
Security
Major
5 months ago 4 years old
Seen in 1 file
1

Potential usage of DES, RC4, MD5 or SHA1

GSC-G401
Security
Major
5 months ago 4 years old
Seen in 7 files
7

Poor file permissions used when creating a directory

GSC-G301
Security
Major
5 months ago 4 years old
Seen in 18 files
36

Potentially bad TLS connection settings

GSC-G402
Security
Major
5 months ago 4 years old
Seen in 7 files
9

Poor file permissions used when creating a file or using os.Chmod

GSC-G302
Security
Major
5 months ago 3 years old
Seen in 6 files
6

Audit the random number generation source (rand)

GSC-G404
Security
Minor
5 months ago 3 years old
Seen in 5 files
7

Audit the usage of unescaped data in HTML templates

GSC-G203
Security
Major
5 months ago 3 years old
Seen in 1 file
1

File path traversal when extracting zip archive

GSC-G305
Security
Minor
5 months ago 3 years old
Seen in 1 file
1

MinVersion is missing from this TLS configuration

GO-S1020
Security
Major
5 months ago 2 years old
Seen in 7 files
9

Audit required: SHA1 cipher algorithm is cryptographically broken

GO-S1025
Security
Major
5 months ago 2 years old
Seen in 1 file
1

Audit required: MD5 cipher algorithm is cryptographically broken

GO-S1023
Security
Major
5 months ago 2 years old
Seen in 6 files
6

Use net.JoinHostPort instead of fmt.Sprintf(...)

GO-S1027
Security
Major
5 months ago 2 years old
Seen in 3 files
3

Potential DoS vulnerability via decompression bomb

GO-S2110
Security
Critical
5 months ago a year old
Seen in 2 files
3

RSA key length less than 2048 bits

GSC-G403
Security
Major
5 months ago a year old
Seen in 1 file
1

http.NewRequest request send to http:// URLs

GO-S1028
Security
Major
5 months ago a year old
Seen in 2 files
4

Using a cost factor of less than 10 for bcrypt

GO-S1045
Security
Major
5 months ago a year old
Seen in 1 file
1

Use of net/http's ListenAndServe function has no support for setting timeouts

GO-S2114
Security
Major
5 months ago a year old
Seen in 1 file
1

Random number generator seed doesn't have enough entropy

GO-S1033
Security
Major
5 months ago a year old
Seen in 1 file
1

Potential slowloris attack

GO-S2112
Security
Major
5 months ago a year old
Seen in 1 file
1

Import blacklist: crypto/sha1

GSC-G505
Security
Major
5 months ago 4 years old
Seen in 1 file
1

Audit required: Exposure of directory listing using net/http.FileServer

GO-S1034
Security
Major
5 months ago 5 months old
Seen in 1 file
1