rapid7/metasploit-framework

View on GitHub

Showing 22,177 of 22,177 total issues

Avoid too many return statements within this method.
Open

        return [false, 'Failed to deescalate privileges. Manual cleanup is required.']
Severity: Major
Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

    Avoid too many return statements within this method.
    Open

            return deal_with_failure_by_mode(mode, "Failed to parse the users.xml file while attempting to #{deescalate ? 'deescalate' : 'escalate'} privileges: #{e}", 'unexpected_reply')
    Severity: Major
    Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

      Avoid too many return statements within this method.
      Open

            return CheckCode::Detected("Exploitation requires privilege escalation, which is not possible for OpenNMS version #{version}.")
      Severity: Major
      Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

        Avoid too many return statements within this method.
        Open

                  return deal_with_failure_by_mode(mode, message, 'unexpected_reply')
        Severity: Major
        Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

          Avoid too many return statements within this method.
          Open

                return CheckCode::Appears("User #{username} has #{@highest_priv} privileges. Exploitation is likely possible via privilege escalation to ROLE_FILESYSTEM_EDITOR.")
          Severity: Major
          Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

            Avoid too many return statements within this method.
            Open

                    return [true, 'Received expected response while triggering the payload. Please be patient, it may take a few seconds for the payload to execute.']
            Severity: Major
            Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

              Avoid too many return statements within this method.
              Open

                  return [false, privs_or_msg] unless success
              Severity: Major
              Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

                Avoid too many return statements within this method.
                Open

                      return Exploit::CheckCode::Safe
                Severity: Major
                Found in modules/exploits/linux/http/dlink_hnap_bof.rb - About 30 mins to fix

                  Avoid too many return statements within this method.
                  Open

                        return [false, "Received unexpected response while attempting to trigger the notification. The payload likely wasn't executed."]
                  Severity: Major
                  Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

                    Avoid too many return statements within this method.
                    Open

                            return deal_with_failure_by_mode(mode, "Received unexpected reply while attempting to #{deescalate ? 'deescalate' : 'escalate'} privileges", 'unexpected_reply')
                    Severity: Major
                    Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

                      Avoid too many return statements within this method.
                      Open

                            return
                      Severity: Major
                      Found in modules/exploits/linux/http/panos_readsessionvars.rb - About 30 mins to fix

                        Avoid too many return statements within this method.
                        Open

                                return deal_with_failure_by_mode(mode, message, 'unexpected_reply')
                        Severity: Major
                        Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

                          Avoid too many return statements within this method.
                          Open

                                return
                          Severity: Major
                          Found in modules/exploits/linux/http/panos_readsessionvars.rb - About 30 mins to fix

                            Avoid too many return statements within this method.
                            Open

                                return privs_or_check_code unless success
                            Severity: Major
                            Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

                              Avoid too many return statements within this method.
                              Open

                                    return CheckCode::Appears(
                                      "Netsweeper #{version} is a vulnerable version."
                                    )
                              Severity: Major
                              Found in modules/exploits/linux/http/netsweeper_webadmin_unixlogin.rb - About 30 mins to fix

                                Avoid too many return statements within this method.
                                Open

                                      return CheckCode::Safe("User #{username} does not have the required privileges for exploitation to work.")
                                Severity: Major
                                Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

                                  Avoid too many return statements within this method.
                                  Open

                                        return
                                  Severity: Major
                                  Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

                                    Avoid too many return statements within this method.
                                    Open

                                          return [false, message] unless success # this is only used for cleanup. for exploit this cannot happen
                                    Severity: Major
                                    Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

                                      Avoid too many return statements within this method.
                                      Open

                                            return CheckCode::Unknown("Failed to obtain a valid OpenNMS version: #{e}")
                                      Severity: Major
                                      Found in modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb - About 30 mins to fix

                                        Avoid too many return statements within this method.
                                        Open

                                                return CheckCode::Appears if revision.to_i < 3
                                        Severity: Major
                                        Found in modules/exploits/linux/http/bitbucket_git_cmd_injection.rb - About 30 mins to fix
                                          Severity
                                          Category
                                          Status
                                          Source
                                          Language