Funding Circle Checks / fc-checks/coberos
succeeded
Apr 26, 2024 in 20s
Coberos found 1 error(s)
Scan should block, but passed since it is in production
Annotations
Check failure on line 146 in spec/hellgrid_spec.rb
funding-circle-checks / fc-checks/coberos
ruby.lang.security.dangerous-subshell.dangerous-subshell
Detected non-static command inside `...`. If unverified user data can reach this call site, this is
a code injection vulnerability. A malicious actor can inject a malicious script to execute arbitrary
code.
Raw output
Fingerprint: cfe59e475c1a35e0a708b0ec8b9be93fa53eeeefb78c5020adb1ed70326a02bd
Category: CWE-94 Improper Control of Generation of Code ('Code Injection')
Loading