Type:
Improvement
Status:
Open
Priority:
Major
Resolution:
Will Fix
Affects Version/s:
None
Component/s:
None
Veracode security report 8/2020- , recommendation to fix i2b2-webclient code to fix High Security flaws to be policy compliant
Module Name Compiler Operating Environment
JS files within i2b2-webclient.zip JAVASCRIPT_5_1 JavaScript
PHP files within i2b2-webclient.zip PHP_5 PHP
List of identified Files:
Module Location
PHP files within i2b2-webclient.zip i2b2-webclient/.../admin.php 83
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 238
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 3303
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 3323
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 3947
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 3957
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 4767
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 5025
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 5038
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 5047
PHP files within i2b2-webclient.zip i2b2-webclient/.../helper.php 62
PHP files within i2b2-webclient.zip i2b2-webclient/.../helper.php 186
PHP files within i2b2-webclient.zip i2b2-webclient/index.php 212
PHP files within i2b2-webclient.zip .../installConfirm.php 65
PHP files within i2b2-webclient.zip .../installConfirm.php 78
PHP files within i2b2-webclient.zip .../installConfirm.php 98
PHP files within i2b2-webclient.zip i2b2-webclient/.../admin.php 83
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 238
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 3303
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 3323
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 3947
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 3957
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 4767
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 5025
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 5038
JS files within i2b2- webclient.zip /i2b2-webclient/.../c3code/c3.js 5047
PHP files within i2b2-webclient.zip i2b2-webclient/.../helper.php 62
PHP files within i2b2-webclient.zip i2b2-webclient/.../helper.php 186
PHP files within i2b2-webclient.zip i2b2-webclient/index.php 212
PHP files within i2b2-webclient.zip .../installConfirm.php 65
PHP files within i2b2-webclient.zip .../installConfirm.php 78
PHP files within i2b2-webclient.zip .../installConfirm.php 98
No work has yet been logged on this issue.
{"report":{"fcp":1393.699999999255,"ttfb":298.8999999985099,"pageVisibility":"visible","entityId":11681,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":16,"apdex":0.5,"journeyId":"3af89be2-d042-4da9-8528-10bec06dba6f","navigationType":0,"readyForUser":1469.5,"redirectCount":0,"resourceLoadedEnd":1805.2999999988824,"resourceLoadedStart":307.5,"resourceTiming":[{"duration":640,"initiatorType":"link","name":"https://community.i2b2.org/jira/s/7fd763ecdf5ed1f47fc4d22fa8382e97-CDN/4x9nqn/820011/16zrvj4/49fa3aa3d35a2cc689cbf274e66cc41a/_/download/contextbatch/css/_super/batch.css","startTime":307.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":307.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":947.5,"responseStart":0,"secureConnectionStart":0},{"duration":639.9000000003725,"initiatorType":"link","name":"https://community.i2b2.org/jira/s/898b8076c5e82f53cd816ca393e45a56-CDN/4x9nqn/820011/16zrvj4/f614b50eeb842ebd1ea7ab2903699907/_/download/contextbatch/css/project.issue.navigator,jira.view.issue,jira.global,atl.general,-_super/batch.css?jira.create.linked.issue=true&richediton=true","startTime":307.7999999988824,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":307.7999999988824,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":947.6999999992549,"responseStart":0,"secureConnectionStart":0},{"duration":708.3000000007451,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/4c9c503fe98f210445831b0d7b0cdc33-CDN/4x9nqn/820011/16zrvj4/49fa3aa3d35a2cc689cbf274e66cc41a/_/download/contextbatch/js/_super/batch.js?locale=en-US","startTime":307.8999999985099,"connectEnd":307.8999999985099,"connectStart":307.8999999985099,"domainLookupEnd":307.8999999985099,"domainLookupStart":307.8999999985099,"fetchStart":307.8999999985099,"redirectEnd":0,"redirectStart":0,"requestStart":307.8999999985099,"responseEnd":1016.1999999992549,"responseStart":1016.1999999992549,"secureConnectionStart":307.8999999985099},{"duration":750.3000000007451,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/694e598c1ae48b0f96655173631cd247-CDN/4x9nqn/820011/16zrvj4/f614b50eeb842ebd1ea7ab2903699907/_/download/contextbatch/js/project.issue.navigator,jira.view.issue,jira.global,atl.general,-_super/batch.js?jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":308.2999999988824,"connectEnd":308.2999999988824,"connectStart":308.2999999988824,"domainLookupEnd":308.2999999988824,"domainLookupStart":308.2999999988824,"fetchStart":308.2999999988824,"redirectEnd":0,"redirectStart":0,"requestStart":308.2999999988824,"responseEnd":1058.5999999996275,"responseStart":1058.5999999996275,"secureConnectionStart":308.2999999988824},{"duration":752.6000000014901,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/53f54e0ac3f00bb56b136b4d2fff2853-CDN/4x9nqn/820011/16zrvj4/aae1242f5fc81cc6a5bb8bc963ccda29/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en-US","startTime":308.3999999985099,"connectEnd":308.3999999985099,"connectStart":308.3999999985099,"domainLookupEnd":308.3999999985099,"domainLookupStart":308.3999999985099,"fetchStart":308.3999999985099,"redirectEnd":0,"redirectStart":0,"requestStart":308.3999999985099,"responseEnd":1061,"responseStart":1061,"secureConnectionStart":308.3999999985099},{"duration":753.4000000003725,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/d41d8cd98f00b204e9800998ecf8427e-CDN/4x9nqn/820011/16zrvj4/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":308.59999999962747,"connectEnd":308.59999999962747,"connectStart":308.59999999962747,"domainLookupEnd":308.59999999962747,"domainLookupStart":308.59999999962747,"fetchStart":308.59999999962747,"redirectEnd":0,"redirectStart":0,"requestStart":308.59999999962747,"responseEnd":1062,"responseStart":1062,"secureConnectionStart":308.59999999962747},{"duration":754.0999999996275,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/d41d8cd98f00b204e9800998ecf8427e-CDN/4x9nqn/820011/16zrvj4/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":308.7999999988824,"connectEnd":308.7999999988824,"connectStart":308.7999999988824,"domainLookupEnd":308.7999999988824,"domainLookupStart":308.7999999988824,"fetchStart":308.7999999988824,"redirectEnd":0,"redirectStart":0,"requestStart":308.7999999988824,"responseEnd":1062.8999999985099,"responseStart":1062.8999999985099,"secureConnectionStart":308.7999999988824},{"duration":773.1000000014901,"initiatorType":"link","name":"https://community.i2b2.org/jira/s/30748292e4ca68be6947d7969829384b-CDN/4x9nqn/820011/16zrvj4/4f66da484ef7d95a2a604d3ab014374c/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":308.8999999985099,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":308.8999999985099,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1082,"responseStart":0,"secureConnectionStart":0},{"duration":754.7999999988824,"initiatorType":"script","name":"https://community.i2b2.org/jira/rest/api/1.0/shortcuts/820011/766848d8ff8ea3676a80e44dfb51696a/shortcuts.js?context=issuenavigation&context=issueaction","startTime":309,"connectEnd":309,"connectStart":309,"domainLookupEnd":309,"domainLookupStart":309,"fetchStart":309,"redirectEnd":0,"redirectStart":0,"requestStart":309,"responseEnd":1063.7999999988824,"responseStart":1063.7999999988824,"secureConnectionStart":309},{"duration":754.1999999992549,"initiatorType":"link","name":"https://community.i2b2.org/jira/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/4x9nqn/820011/16zrvj4/efa42a25652b26dfd802540c024826b3/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.css?jira.create.linked.issue=true&richediton=true","startTime":328,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":328,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1082.199999999255,"responseStart":0,"secureConnectionStart":0},{"duration":739.0999999996275,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/8087506fefd02b4096991c90836b49f6-CDN/4x9nqn/820011/16zrvj4/efa42a25652b26dfd802540c024826b3/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.js?jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":328.19999999925494,"connectEnd":328.19999999925494,"connectStart":328.19999999925494,"domainLookupEnd":328.19999999925494,"domainLookupStart":328.19999999925494,"fetchStart":328.19999999925494,"redirectEnd":0,"redirectStart":0,"requestStart":328.19999999925494,"responseEnd":1067.2999999988824,"responseStart":1067.2999999988824,"secureConnectionStart":328.19999999925494},{"duration":1448.2999999988824,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/d41d8cd98f00b204e9800998ecf8427e-CDN/4x9nqn/820011/16zrvj4/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":336.5,"connectEnd":336.5,"connectStart":336.5,"domainLookupEnd":336.5,"domainLookupStart":336.5,"fetchStart":336.5,"redirectEnd":0,"redirectStart":0,"requestStart":336.5,"responseEnd":1784.7999999988824,"responseStart":1784.7999999988824,"secureConnectionStart":336.5},{"duration":1464.2999999988824,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/d41d8cd98f00b204e9800998ecf8427e-CDN/4x9nqn/820011/16zrvj4/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":341,"connectEnd":341,"connectStart":341,"domainLookupEnd":341,"domainLookupStart":341,"fetchStart":341,"redirectEnd":0,"redirectStart":0,"requestStart":341,"responseEnd":1805.2999999988824,"responseStart":1805.2999999988824,"secureConnectionStart":341},{"duration":542.9000000003725,"initiatorType":"xmlhttprequest","name":"https://community.i2b2.org/jira/rest/webResources/1.0/resources","startTime":1299.2999999988824,"connectEnd":1299.2999999988824,"connectStart":1299.2999999988824,"domainLookupEnd":1299.2999999988824,"domainLookupStart":1299.2999999988824,"fetchStart":1299.2999999988824,"redirectEnd":0,"redirectStart":0,"requestStart":1299.2999999988824,"responseEnd":1842.199999999255,"responseStart":1842.199999999255,"secureConnectionStart":1299.2999999988824}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":246,"connectEnd":271,"secureConnectionStart":259,"requestStart":271,"responseStart":299,"responseEnd":341,"domLoading":302,"domInteractive":1823,"domContentLoadedEventStart":1823,"domContentLoadedEventEnd":1892,"domComplete":2263,"loadEventStart":2263,"loadEventEnd":2263,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1807.5},{"name":"bigPipe.sidebar-id.end","time":1808.3999999985099},{"name":"bigPipe.activity-panel-pipe-id.start","time":1808.5},{"name":"bigPipe.activity-panel-pipe-id.end","time":1809.0999999996275},{"name":"activityTabFullyLoaded","time":1902.8999999985099}],"measures":[],"correlationId":"eebeb62d06d16b","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":55,"dbReadsTimeInMs":5,"dbConnsTimeInMs":8,"applicationHash":"0629dd8d260e3954ece49053e565d01dabe11609","experiments":[]}}