Finding Overview
The following table summarizes the results of the audit:
Type | Status | Name | Summary | Severity (Score) |
---|---|---|---|---|
Vulnerability |
fixed |
Due to usage of |
critical (9) |
|
Vulnerability |
fixed |
The custom implemented Tauri command |
low (2) |
|
Weakness |
fixed |
The |
high (8.2) |
|
Weakness |
open |
The application facilitates a permissive allow list configuration, which imports and enables unused Tauri API endpoints. |
medium (6.2) |
|
Weakness |
fixed |
Application dependencies have their own telemetry system, which is not documented, disabled or controlled by the bloop application. |
low (3.7) |
|
Weakness |
open |
The application is missing a Content Security policy to add a defense-in-depth layer against adversaries. |
low (3.1) |
|
Weakness |
fixed |
Due to outdated packages in the frontend, the application is at risk of vulnerabilities in these dependencies. |
low (2.5) |
|
Weakness |
open |
Some of the Rust crates possess vulnerabilies or are unmaintained. The application is at risk through these dependencies. |
low (2.5) |
Investigated Components
The following list summarizes the code parts investigated during the audit, which did not result in a finding.