Skip to content

Develop#76

Merged
benjamin-lam merged 2 commits intomasterfrom
develop
Jan 24, 2025
Merged

Develop#76
benjamin-lam merged 2 commits intomasterfrom
develop

Conversation

@benjamin-lam
Copy link
Contributor

Release Changes 3.2.4

Changed

  • Updated CSP Whitelist
  • Added deprecated warnings for Heidelpay / CSP

@github-actions
Copy link

Logo
Checkmarx One – Scan Summary & Details1f9d1fae-ece0-4a5a-9060-e238dcf9213f

New Issues (7)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
CRITICAL Cx5aa6edea-ffde Php-phpunit/phpunit-6.2.4 Vulnerable Package
MEDIUM Missing_HSTS_Header /Block/System/Config/WebhooksApplepayButtons.php: 91
detailsThe web-application does not define an HSTS header, leaving it vulnerable to attack.
Attack Vector
LOW Client_Hardcoded_Domain /view/frontend/web/js/view/payment/method-renderer/base.js: 2
detailsThe JavaScript file imported in js in /view/frontend/web/js/view/payment/method-renderer/base.js at line 2 is from a remote domain, which may allow...
Attack Vector
LOW Client_Hardcoded_Domain /view/frontend/web/js/model/checkout/threat-metrix.js: 41
detailsThe JavaScript file imported in "https://h\.online\-metrix\.net/fp/tags\.js?org\_id=363t8kgq&session\_id=" in /view/frontend/web/js/model/checkout/threat...
Attack Vector
LOW Client_Hardcoded_Domain /view/frontend/web/js/model/checkout/threat-metrix.js: 46
detailsThe JavaScript file imported in "https://h\.online\-metrix\.net/fp/tags?org\_id=363t8kgq&session\_id=" in /view/frontend/web/js/model/checkout/threat-me...
Attack Vector
LOW Client_Hardcoded_Domain /view/frontend/web/js/model/checkout/threat-metrix.js: 46
detailsThe JavaScript file imported in "https://h\.online\-metrix\.net/fp/tags?org\_id=363t8kgq&session\_id=" in /view/frontend/web/js/model/checkout/threat-me...
Attack Vector
LOW Client_Use_Of_Iframe_Without_Sandbox /view/frontend/web/js/model/checkout/threat-metrix.js: 45
detailsThe application employs an HTML iframe at whose contents are not properly sandboxed
Attack Vector

@benjamin-lam benjamin-lam merged commit 580751f into master Jan 24, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant