Skip to content

Bug #15721 : Collect - Metadata file error message issue#3643

Merged
hazco75 merged 1 commit intodevelopfrom
bug_15721_collect
Mar 30, 2026
Merged

Bug #15721 : Collect - Metadata file error message issue#3643
hazco75 merged 1 commit intodevelopfrom
bug_15721_collect

Conversation

@hazco75
Copy link
Copy Markdown
Contributor

@hazco75 hazco75 commented Mar 27, 2026

Description

Uniformiser les messages d'erreur lors de la création et de la modification d'un projet avec un fichier metadata vide

@hazco75 hazco75 added this to the IT 167 milestone Mar 27, 2026
@hazco75 hazco75 added bug Something isn't working small pr embarquant peu de changements et à review rapide, ne nécessitant qu'un reviewer labels Mar 27, 2026
@vitam-prg
Copy link
Copy Markdown
Collaborator

Logo
Checkmarx One – Scan Summary & Details1a387c26-39d5-4f25-bace-b9cfa9041317


New Issues (9) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 HIGH CVE-2026-33870 Maven-io.netty:netty-codec-http-4.1.104.Final
detailsRecommended version: 4.2.10.Final
Description: Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Affected versio...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
2 HIGH CVE-2026-33870 Maven-io.netty:netty-codec-http-4.1.131.Final
detailsDescription: Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Affected versio...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
3 HIGH CVE-2026-33871 Maven-io.netty:netty-codec-http2-4.1.104.Final
detailsDescription: A remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
4 HIGH CVE-2026-33871 Maven-io.netty:netty-codec-http2-4.1.131.Final
detailsDescription: A remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
5 HIGH CVE-2026-33891 Npm-node-forge-1.3.3
detailsDescription: A Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the "BigInteger.modInverse()" function (inherit...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
6 HIGH CVE-2026-33895 Npm-node-forge-1.3.3
detailsDescription: Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (S >= L). A valid s...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
7 HIGH CVE-2026-33896 Npm-node-forge-1.3.3
detailsDescription: `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstr...
Attack Vector: NETWORK
Attack Complexity: HIGH
Vulnerable Package
8 HIGH CVE-2026-4926 Npm-path-to-regexp-0.1.7
detailsDescription: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as "{a}{b}{c}:z". The genera...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package
9 HIGH CVE-2026-4926 Npm-path-to-regexp-0.1.12
detailsDescription: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as "{a}{b}{c}:z". The genera...
Attack Vector: NETWORK
Attack Complexity: LOW
Vulnerable Package

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

@hazco75 hazco75 merged commit 77f70df into develop Mar 30, 2026
17 of 18 checks passed
@hazco75 hazco75 deleted the bug_15721_collect branch March 30, 2026 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working small pr embarquant peu de changements et à review rapide, ne nécessitant qu'un reviewer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants