Security findings by project
Based on the last completed scan. The same issue is counted once.
| Project | Secrets | Secure coding | Open source vulns | Licenses | Total | Last scan | AI false positives |
|---|---|---|---|---|---|---|---|
| payment-api | 1 | 7 | 4 | 1 | 13 | 2026-10-10 09:05 | 2 |
| partner-portal | 0 | 5 | 2 | 0 | 7 | 2026-10-09 18:42 | 1 |
| batch-settlement | 2 | 3 | 6 | 1 | 12 | 2026-10-08 11:20 | 0 |
In this demo, you can open the results of the payment-api project.
Dashboard / payment-api
payment-api
13 open findings · Findings from the same rule are grouped together.
SQL query built by string concatenationCWE-89HIGH2
src/main/java/com/sample/payment/order/OrderRepository.java:48Newsrc/main/java/com/sample/payment/refund/RefundRepository.java:73
Sensitive data written to logsCWE-532MEDIUM3
src/main/java/com/sample/payment/PaymentService.java:112src/main/java/com/sample/payment/log/LogMasking.java:21AI: likely false positivesrc/main/java/com/sample/payment/card/CardController.java:88
Path traversalCWE-22HIGH1
src/main/java/com/sample/payment/file/FileController.java:57AI: likely false positive
Predictable random valuesCWE-330MEDIUM1
src/main/java/com/sample/payment/auth/TokenGenerator.java:19
log4j-core remote code executionCVE-2021-44228CRITICAL1
org.apache.logging.log4j:log4j-core 2.14.1· Upgrade to 2.17.1 or later
spring-beans remote code executionCVE-2022-22965CRITICAL1
org.springframework:spring-beans 5.3.17· Upgrade to 5.3.18 or later
commons-text string interpolation remote code executionCVE-2022-42889CRITICAL1
org.apache.commons:commons-text 1.9· Upgrade to 1.10.0 or later
jackson-databind denial of service via deep nestingCVE-2020-36518HIGH1
com.fasterxml.jackson.core:jackson-databind 2.13.1· Upgrade to 2.13.2.1 or later
Exposed cloud access keyCRITICAL1
src/main/resources/application-prod.yml:12· Shown maskedAKIA••••••••
Strong copyleft componentAGPL-3.0HIGH1
com.itextpdf:kernel 7.2.5· Depending on how the service is offered, source disclosure may be required. Legal review is recommended.
In this demo, you can open the detail of OrderRepository.java:48.
Dashboard / payment-api / Finding
SQL query built by string concatenation
src/main/java/com/sample/payment/order/OrderRepository.java:48
Location
46public List<Order> findByCustomer(String customerId) {
47 // Orders by customer
48 String sql = "SELECT * FROM orders WHERE customer_id = '" + customerId + "'";49 return jdbcTemplate.query(sql, orderMapper);
50}
Why it matters
When external input is concatenated into a SQL statement, an attacker can inject SQL into that input to read other customers' orders or change data.
How to fix it
Pass values as bind parameters (?) instead of concatenating strings. The statement and the values stay separate, so input is never interpreted as SQL.
Summary
- Severity
- HIGH
- Category
- Secure coding
- Type
- CWE-89 SQL injection
- Status
- New
- First seen
- 2026-10-10
customerId flows from the request into the SQL statement without validation. This location can be exploited.
Suggested fix
- String sql = "SELECT * FROM orders WHERE customer_id = '" + customerId + "'";
- return jdbcTemplate.query(sql, orderMapper);
+ String sql = "SELECT * FROM orders WHERE customer_id = ?";
+ return jdbcTemplate.query(sql, orderMapper, customerId);
AI judgments are suggestions. A reviewer makes the final call.
AI false positives
Findings that AI judged likely to be false positives. Once a reviewer confirms them against the evidence, they are removed from the counts.