🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: ha-process-engine4
Branch: feature/dev-2
Build: #124
Date: 2026-02-20 16:12:32

0

Critical

4

High

4

Medium

0

Low

5

Secrets

1

Misconfig

🔴 Vulnerabilities (7)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2025-67735 io.netty:netty-codec-http 4.1.126.Final 4.2.8.Final, 4.1.129.Final netty-codec-http: Netty (netty-codec-http): Request Smuggling via CRLF Injection
HIGH CVE-2025-48989 org.apache.tomcat.embed:tomcat-embed-core 10.1.42 11.0.10, 10.1.44, 9.0.108 tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames
HIGH CVE-2025-55752 org.apache.tomcat.embed:tomcat-embed-core 10.1.42 11.0.11, 10.1.45, 9.0.109 tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possi
MEDIUM CVE-2025-66614 org.apache.tomcat.embed:tomcat-embed-core 10.1.42 11.0.14, 10.1.49, 9.0.112 tomcat: Client certificate verification bypass due to virtual host mapping
HIGH CVE-2025-41249 org.springframework:spring-core 6.2.8 6.2.11 org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability
MEDIUM CVE-2025-41242 org.springframework:spring-webmvc 6.2.8 6.2.10 org.springframework/spring-webmvc: Spring Framework MVC path traversal vulnerability
MEDIUM CVE-2025-41254 org.springframework:spring-websocket 6.2.8 6.2.12 org.springframework/spring-core: Spring Framework STOMP CSRF Vulnerability
🔑 Secrets (5)
TypeFileLineMatch
AWS .env 16 # S3_ACCESS_ID=********************...
AWS security-reports/gitleaks-report.json 93 "Match": "********************",...
AWS security-reports/gitleaks-report.json 94 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 198 "Match": "********************",...
AWS security-reports/gitleaks-report.json 199 "Secret": "********************",...
⚙️ Misconfigurations (1)
SeverityIDCheckFileMessage
HIGH DS-0002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)