Skip to content

Update checkmarx-ast-cli binaries with 2.3.47#475

Open
cx-anurag-dalke wants to merge 2 commits intomainfrom
feature/update_cli_2.3.47
Open

Update checkmarx-ast-cli binaries with 2.3.47#475
cx-anurag-dalke wants to merge 2 commits intomainfrom
feature/update_cli_2.3.47

Conversation

@cx-anurag-dalke
Copy link
Collaborator

Updates checkmarx-ast-cli to 2.3.47

Auto-generated by [create-pull-request][2]

@cx-yevgeny-kuznetsov
Copy link

cx-yevgeny-kuznetsov commented Mar 17, 2026

Logo
Checkmarx One – Scan Summary & Details99605bad-c77c-4f3f-a83d-d121b7ac6653


New Issues (3) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 HIGH Cxfa47c4e4-5ef9 Maven-com.fasterxml.jackson.core:jackson-core-2.16.1
detailsRecommended version: 2.18.6
Description: The non-blocking (async) JSON parser in jackson-core bypasses the "maxNumberLength" constraint (default: 1000 characters) defined in "StreamReadCon...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 HIGH Reversible_One_Way_Hash /src/main/java/com/checkmarx/ast/wrapper/Execution.java: 36
detailsThe application is using a weak hashing primitive getInstance, in /src/main/java/com/checkmarx/ast/wrapper/Execution.java at line 207
Attack Vector
3 MEDIUM Stored_Command_Argument_Injection /src/main/java/com/checkmarx/ast/wrapper/CxWrapper.java: 471
detailsAn argument is passed to an external OS command by start at /src/main/java/com/checkmarx/ast/wrapper/CxWrapper.java in line 512. This could allow...
Attack Vector

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants