Skip to content

Dev2 - #9

Open
davidka91 wants to merge 8 commits into
mainfrom
dev
Open

Dev2#9
davidka91 wants to merge 8 commits into
mainfrom
dev

Conversation

@davidka91

Copy link
Copy Markdown
Owner

trying again

@davidka91

Copy link
Copy Markdown
Owner Author

🚨 Frogbot scanned this pull request and found the below:

📗 Scan Summary

  • Frogbot scanned for violations and found 34 issues
Scan Category Status Security Issues
Software Composition Analysis ✅ Done
34 Issues Found 1 Critical
5 High
28 Medium
Contextual Analysis ✅ Done -
Static Application Security Testing (SAST) ✅ Done Not Found
Secrets ✅ Done -
Infrastructure as Code (IaC) ✅ Done Not Found

🚥 Policy Violations

🚨 Security Violations

Severity ID Contextual Analysis Direct Dependencies Impacted Dependency Watch Name
critical
Critical
CVE-2025-10156 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
high
High
CVE-2025-10155 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
high
High
CVE-2025-10157 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
high
High
XRAY-714109 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
high
High
CVE-2025-46417 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718829 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718828 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718827 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718826 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718825 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718824 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718823 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718822 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718821 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718820 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718812 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718811 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718810 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718809 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718808 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718807 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718806 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718805 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718804 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718803 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718802 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718040 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718039 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718038 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718037 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718036 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718035 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
medium
Medium
XRAY-718034 Not Covered picklescan:0.0.24 picklescan:0.0.24 frogbot
high (not applicable)
High
CVE-2023-30861 Not Applicable flask:2.2.2 flask:2.2.2 frogbot

🔖 Details

[ CVE-2025-10156 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.31]
CVSS V3: 9.8

An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This is achieved by crafting a ZIP archive containing a file with a bad Cyclic Redundancy Check (CRC), which causes the scanner to halt and fail to analyze the contents for malicious pickle files. When the file incorrectly considered safe is loaded, it can lead to the execution of malicious code.

[ CVE-2025-10155 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.31]
CVSS V3: 7.8

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly considered safe is loaded, it can lead to the execution of malicious code.

[ CVE-2025-10157 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.31]
CVSS V3: 7.8

A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check. This is possible because the scanner performs an exact match for module names, allowing malicious payloads to be loaded via submodules of dangerous packages (e.g., 'asyncio.unix_events' instead of 'asyncio').

When the incorrectly considered safe file is loaded after scan, it can lead to the execution of malicious code.

[ XRAY-714109 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.27]
CVSS V3: -

Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

[ CVE-2025-46417 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.25]
CVSS V3: 7.5

The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.

[ XRAY-718829 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.30]
CVSS V3: -

Picklescan is missing detection when calling built-in python library asyncio.unix_events._UnixSubprocessTransport._start

[ XRAY-718828 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.30]
CVSS V3: -

Picklescan is missing detection when calling built-in python cProfile.run

[ XRAY-718827 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.30]
CVSS V3: -

Picklescan is missing detection when calling built-in python cProfile.runctx

[ XRAY-718826 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.30]
CVSS V3: -

Picklescan is missing detection when calling built-in python doctest.debug_script

[ XRAY-718825 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.30]
CVSS V3: -

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode

[ XRAY-718824 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.30]
CVSS V3: -

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

[ XRAY-718823 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.30]
CVSS V3: -

Picklescan is missing detection when calling built-in python idlelib.run.Executive.runcode

[ XRAY-718822 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.30]
CVSS V3: -

Picklescan is missing detection when calling built-in python lib2to3.pgen2.pgen.ParserGenerator.make_label

[ XRAY-718821 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.30]
CVSS V3: -

Picklescan is missing detection when calling built-in python ensurepip._run_pip

[ XRAY-718820 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.30]
CVSS V3: -

Picklescan is missing detection when calling pytorch function torch.utils.bottleneck.main.run_autograd_prof

[ XRAY-718812 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.29]
CVSS V3: -

Picklescan has a missing detection when calling built-in python library idlelib.calltip.get_entity

[ XRAY-718811 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.29]
CVSS V3: -

Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip

[ XRAY-718810 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.29]
CVSS V3: -

Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter

[ XRAY-718809 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.29]
CVSS V3: -

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

[ XRAY-718808 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.29]
CVSS V3: -

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity

[ XRAY-718807 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.29]
CVSS V3: -

Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem

[ XRAY-718806 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.29]
CVSS V3: -

Picklescan has a missing detection when calling built-in python lib2to3.pgen2.grammar.Grammar.loads

[ XRAY-718805 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.29]
CVSS V3: -

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

[ XRAY-718804 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.29]
CVSS V3: -

Picklescan has a missing detection when calling built-in python profile.Profile.run

[ XRAY-718803 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.29]
CVSS V3: -

Picklescan has a missing detection when calling built-in python trace.Trace.runctx

[ XRAY-718802 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.29]
CVSS V3: -

Picklescan has a missing detection when calling built-in python trace.Trace.run

[ XRAY-718040 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.28]
CVSS V3: -

Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config

[ XRAY-718039 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.28]
CVSS V3: -

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

[ XRAY-718038 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.28]
CVSS V3: -

Picklescan missing detection when calling pytorch function torch.utils.data.datapipes.utils.decoder.basichandlers

[ XRAY-718037 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.28]
CVSS V3: -

Picklescan missing detection when calling pytorch function torch.utils.collect_env.run

[ XRAY-718036 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.28]
CVSS V3: -

Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression

[ XRAY-718035 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.28]
CVSS V3: -

Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get

[ XRAY-718034 ] picklescan 0.0.24 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Contextual Analysis: Not Covered
Direct Dependencies: picklescan:0.0.24
Impacted Dependency: picklescan:0.0.24
Fixed Versions: [0.0.28]
CVSS V3: -

Picklescan missing detection when calling pytorch function torch.utils.bottleneck.main.run_cprofile

[ CVE-2023-30861 ] flask 2.2.2 (frogbot)

Violation Details

Policies: frogbot
Watch Name: frogbot
Jfrog Research Severity: Medium
Contextual Analysis: Not Applicable
Direct Dependencies: flask:2.2.2
Impacted Dependency: flask:2.2.2
Fixed Versions: [2.2.5], [2.3.2]
CVSS V3: 7.5

Persistent session cookies in Flask can lead to data leakage or privilege escalation when the application is hosted behind a caching proxy.

🔬 JFrog Research Details

Description:
Flask is a lightweight web framework for Python used for building web applications.
An issue arises when using a caching proxy that caches cookies (specifically, the Set-Cookie headers) from responses intended for clients. This situation can result in the proxy sending one client's session cookies to other clients, leading to data leakage or even privilege escalation.

The root cause of this issue is the absence of the Vary: Cookie header, which informs the proxy not to cache session cookies when the session is refreshed (i.e., resent to update the expiration) without being accessed or modified. The Vary: Cookie header is typically set when the session is accessed or modified.

To exploit this vulnerability, several specific conditions must be met:

  • The application must be hosted behind a proxy that caches responses along with their cookies.
  • The application must have the session.permanent attribute set to True.
  • The session must not be accessed or modified before the request is made.
  • The SESSION_REFRESH_EACH_REQUEST feature must be enabled (which is the default behavior).
  • The application should not set a Cache-Control header to indicate that a page is private and should not be cached.

Example of vulnerable code:

from flask import Flask, session

app = Flask(__name__)
app.secret_key = 'your_secret_key'

@app.route('/')
def index():
    session.permanent = True
    # Other code logic...
    return privateData(user)

In this example, a Flask application is used, and the session.permanent attribute is set to True. If this application is deployed behind a caching proxy without proper handling of session cookies and caching directives, the issue may be present.

Remediation:

Development mitigations

Add a Cache-Control in all requests/responses sent by the application explicitly instructing the caching proxy not to cache any content:

@app.after_request
def add_cache_control(response):
    response.headers['Cache-Control'] = 'no-store, no-cache, private, must-revalidate, max-age=0'
    return response
Development mitigations

Disable the SESSION_REFRESH_EACH_REQUEST setting of the Flask application:

app = Flask(__name__)
app.config['SESSION_REFRESH_EACH_REQUEST'] = False



Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant