Server Side Injection(SSI) - setInterval() |
User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
57 |
scripts/android-e2e-test.js |
Server Side Injection(SSI) - setInterval() |
User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
104 |
scripts/android-e2e-test.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
29 |
packager/react-packager/src/Server/index.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
14 |
packager/react-packager/src/Server/__tests__/Server-test.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
183 |
packager/react-packager/src/Bundler/Bundle.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
314 |
packager/react-packager/src/Bundler/__tests__/Bundle-test.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
20 |
packager/react-packager/src/AssetServer/index.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
81 |
packager/react-packager/src/AssetServer/index.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
217 |
packager/react-packager/src/node-haste/Module.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
14 |
packager/react-packager/src/node-haste/FileWatcher/index.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
86 |
packager/react-packager/src/node-haste/FileWatcher/index.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
26 |
packager/react-packager/src/node-haste/Cache/index.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
47 |
packager/react-packager/src/node-haste/Cache/index.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
273 |
packager/react-packager/src/node-haste/Cache/__tests__/Cache-test.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
45 |
packager/react-packager/src/Resolver/polyfills/__tests__/loadBundles-test.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
47 |
packager/react-packager/src/Resolver/polyfills/__tests__/loadBundles-test.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
42 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
46 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
50 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setInterval() |
User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
59 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setInterval() |
User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
64 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
72 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
78 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
80 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
84 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
85 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
86 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
87 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
89 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
91 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
94 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
101 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
107 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
113 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
114 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
119 |
IntegrationTests/TimersTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
53 |
IntegrationTests/ReactContentSizeUpdateTest.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
140 |
Examples/UIExplorer/js/TimerExample.js |
Server Side Injection(SSI) - setInterval() |
User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
149 |
Examples/UIExplorer/js/TimerExample.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
193 |
Examples/UIExplorer/js/TimerExample.js |
Server Side Injection(SSI) - setInterval() |
User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
241 |
Examples/UIExplorer/js/TimerExample.js |
Server Side Injection(SSI) - setInterval() |
User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
120 |
Examples/UIExplorer/js/ReactARTExample.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
35 |
Examples/UIExplorer/js/AsyncStorageExample.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
113 |
Examples/UIExplorer/js/RefreshControlExample.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
78 |
Examples/UIExplorer/js/LayoutExample.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
79 |
Examples/UIExplorer/js/LayoutExample.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
80 |
Examples/UIExplorer/js/LayoutExample.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
81 |
Examples/UIExplorer/js/LayoutExample.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
82 |
Examples/UIExplorer/js/LayoutExample.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
109 |
Examples/UIExplorer/js/PullToRefreshViewAndroidExample.android.js |
Server Side Injection(SSI) - setInterval() |
User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
42 |
Examples/UIExplorer/js/ProgressBarAndroidExample.android.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
63 |
Examples/UIExplorer/js/UIExplorerApp.ios.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
57 |
Examples/UIExplorer/js/ActivityIndicatorExample.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
75 |
Examples/UIExplorer/js/UIExplorerApp.android.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
81 |
Examples/UIExplorer/js/UIExplorerApp.android.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
148 |
Examples/UIExplorer/js/NavigationExperimental/NavigationCardStack-NavigationHeader-Tabs-example.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
42 |
Examples/UIExplorer/js/NavigationExperimental/NavigationExperimentalExample.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
105 |
Examples/UIExplorer/js/AnimatedGratuitousApp/AnExApp.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
224 |
Examples/UIExplorer/js/AnimatedGratuitousApp/AnExApp.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
128 |
Libraries/JavaScriptAppEngine/System/JSTimers/JSTimersExecution.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
162 |
Libraries/JavaScriptAppEngine/System/JSTimers/JSTimersExecution.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
201 |
Libraries/JavaScriptAppEngine/System/JSTimers/JSTimersExecution.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
383 |
Libraries/Components/Touchable/Touchable.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
395 |
Libraries/Components/Touchable/Touchable.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
697 |
Libraries/Components/Touchable/Touchable.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
115 |
Libraries/Components/Touchable/TouchableOpacity.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
170 |
Libraries/Components/Touchable/TouchableHighlight.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
212 |
Libraries/Components/WebView/WebView.android.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
385 |
Libraries/Components/WebView/WebView.macos.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
50 |
Libraries/Devtools/setupDevtools.js |
Server Side Injection(SSI) - setInterval() |
User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
57 |
Libraries/Devtools/setupDevtools.js |
Server Side Injection(SSI) - eval() |
User controlled data in eval() can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
69 |
Libraries/Devtools/setupDevtools.js |
Server Side Injection(SSI) - eval() |
User controlled data in eval() can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
123 |
Libraries/Devtools/setupDevtools.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
111 |
Libraries/Inspector/Inspector.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
80 |
Libraries/CustomComponents/Navigator/Navigator.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
104 |
Libraries/CustomComponents/Navigator/Navigation/__tests__/NavigationRouteStack-test.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
73 |
Libraries/Interaction/JSEventLoopWatchdog.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
48 |
Libraries/Interaction/InteractionManager.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
161 |
Libraries/Interaction/InteractionManager.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
56 |
Libraries/Interaction/__tests__/TaskQueue-test.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
99 |
Libraries/Interaction/__tests__/TaskQueue-test.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
108 |
Libraries/Interaction/__tests__/TaskQueue-test.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
206 |
Libraries/Interaction/__tests__/InteractionManager-test.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
265 |
Libraries/Interaction/__tests__/InteractionManager-test.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
90 |
Libraries/vendor/core/Map.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
32 |
Libraries/vendor/core/toIterator.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
28 |
Libraries/Utilities/HMRLoadingView.android.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
35 |
Libraries/Utilities/__tests__/deepFreezeAndThrowOnMutationInDev-test.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
46 |
Libraries/Utilities/__tests__/deepFreezeAndThrowOnMutationInDev-test.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
81 |
Libraries/Utilities/__tests__/deepFreezeAndThrowOnMutationInDev-test.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
90 |
Libraries/Utilities/__tests__/deepFreezeAndThrowOnMutationInDev-test.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
99 |
Libraries/Utilities/__tests__/deepFreezeAndThrowOnMutationInDev-test.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
297 |
Libraries/Animated/src/AnimatedImplementation.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
115 |
Libraries/Experimental/IncrementalExample.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
321 |
Libraries/Experimental/WindowedListView.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
487 |
Libraries/Experimental/WindowedListView.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
494 |
Libraries/Experimental/WindowedListView.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
531 |
Libraries/Experimental/WindowedListView.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
540 |
Libraries/Experimental/WindowedListView.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
675 |
Libraries/Experimental/WindowedListView.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
146 |
Libraries/Experimental/SwipeableRow/SwipeableRow.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
40 |
local-cli/runAndroid/adb.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
63 |
local-cli/runAndroid/runAndroid.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
107 |
local-cli/runAndroid/runAndroid.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
30 |
local-cli/bundle/signedsource.js |
Weak Hash used - SHA1 |
SHA1 is a a weak hash which is known to have collision. Use a strong hashing function. |
21 |
local-cli/bundle/output/meta.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
22 |
local-cli/logIOS/logIOS.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
29 |
local-cli/runIOS/runIOS.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
58 |
local-cli/runIOS/runIOS.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
11 |
local-cli/server/middleware/cpuProfilerMiddleware.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
12 |
local-cli/server/middleware/getFlowTypeCheckMiddleware.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
12 |
local-cli/server/middleware/getDevToolsMiddleware.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
49 |
local-cli/server/middleware/getDevToolsMiddleware.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
11 |
local-cli/server/middleware/systraceProfileMiddleware.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
87 |
local-cli/server/util/launchEditor.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
40 |
react-native-macos-cli/index.js |