[pull] main from microsoft:main #31
44 new alerts including 38 high severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 38 high
- 6 medium
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Code scanning / CodeQL
Incomplete URL scheme check High library
Code scanning / CodeQL
Incomplete multi-character sanitization High library
, which may cause an HTML element injection vulnerability.Code scanning / CodeQL
Incomplete multi-character sanitization High library
, which may cause an HTML element injection vulnerability.Code scanning / CodeQL
Incomplete multi-character sanitization High library
, which may cause an HTML element injection vulnerability.Code scanning / CodeQL
Incomplete multi-character sanitization High library
, which may cause an HTML element injection vulnerability.Code scanning / CodeQL
Overly permissive regular expression range Medium library
Code scanning / CodeQL
Overly permissive regular expression range Medium library
Code scanning / CodeQL
Overly permissive regular expression range Medium library
Code scanning / CodeQL
Incomplete string escaping or encoding High library test
Code scanning / CodeQL
Incomplete URL scheme check High library
Code scanning / CodeQL
Incomplete string escaping or encoding High library
Code scanning / CodeQL
Incomplete string escaping or encoding High library
Code scanning / CodeQL
Useless regular-expression character escape High library
.Code scanning / CodeQL
Incomplete string escaping or encoding High library
Code scanning / CodeQL
Incomplete string escaping or encoding High library
Code scanning / CodeQL
Incomplete string escaping or encoding High library
Code scanning / CodeQL
Incomplete string escaping or encoding High library
Code scanning / CodeQL
Incomplete string escaping or encoding High library
Code scanning / CodeQL
Incomplete URL scheme check High library
Code scanning / CodeQL
Incomplete regular expression for hostnames High library
, has an unescaped '.' before 'prebid[.]org/', so it might match more hosts than expected.Code scanning / CodeQL
Incomplete regular expression for hostnames High library
, has an unescaped '.' before 'adtechus[.]com/', so it might match more hosts than expected.Code scanning / CodeQL
Incomplete regular expression for hostnames High library
, has an unescaped '.' before 'criteo[.]com/cdb', so it might match more hosts than expected.Code scanning / CodeQL
Incomplete regular expression for hostnames High library
, has an unescaped '.' before 'criteo[.]com/delivery/rta', so it might match more hosts than expected.Code scanning / CodeQL
Incomplete regular expression for hostnames High library
, has an unescaped '.' before 'criteo[.]com/delivery/rta', so it might match more hosts than expected.Code scanning / CodeQL
Incomplete regular expression for hostnames High library
, has an unescaped '.' before 'openx[.]net/w/1', so it might match more hosts than expected.