| Conditions | 2 | 
| Paths | 2 | 
| Total Lines | 189 | 
| Code Lines | 113 | 
| Lines | 0 | 
| Ratio | 0 % | 
| Changes | 3 | ||
| Bugs | 0 | Features | 0 | 
Small methods make your code easier to understand, in particular if combined with a good name. Besides, if your method is small, finding a good name is usually much easier.
For example, if you find yourself adding comments to a method's body, this is usually a good sign to extract the commented part to a new method, and use the comment as a starting point when coming up with a good name for this new method.
Commonly applied refactorings include:
If many parameters/temporary variables are present:
| 1 | <?php | ||
| 199 | private function getTestVulnerabilities($withDev = true) | ||
| 200 |     { | ||
| 201 | $vulnerabilities = [ | ||
| 202 | 'league/flysystem' => [ | ||
| 203 | 'version' => '1.0.70', | ||
| 204 | 'advisories' => [ | ||
| 205 | [ | ||
| 206 | 'title' => 'TOCTOU Race Condition enabling remote code execution', | ||
| 207 | 'link' => 'https://github.com/thephpleague/flysystem/security/advisories/GHSA-9f46-5r25-5wfm', | ||
| 208 | 'cve' => 'CVE-2021-32708', | ||
| 209 | ], | ||
| 210 | ], | ||
| 211 | ], | ||
| 212 | 'silverstripe/admin' => [ | ||
| 213 | 'version' => '1.4.5', | ||
| 214 | 'advisories' => [ | ||
| 215 | [ | ||
| 216 | 'title' => 'CVE-2021-36150 - Insert from files link text - Reflective (self) Cross Site ' | ||
| 217 | . 'Scripting', | ||
| 218 | 'link' => 'https://www.silverstripe.org/download/security-releases/CVE-2021-36150', | ||
| 219 | 'cve' => 'CVE-2021-36150', | ||
| 220 | ], | ||
| 221 | ], | ||
| 222 | ], | ||
| 223 | 'silverstripe/assets' => [ | ||
| 224 | 'version' => '1.1.0', | ||
| 225 | 'advisories' => [ | ||
| 226 | [ | ||
| 227 | 'title' => 'CVE-2019-12245: Incorrect access control vulnerability in files uploaded to ' | ||
| 228 | . 'protected folders', | ||
| 229 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2019-12245/', | ||
| 230 | 'cve' => 'CVE-2019-12245', | ||
| 231 | ], | ||
| 232 | [ | ||
| 233 | 'title' => 'CVE-2020-9280: Folders migrated from 3.x may be unsafe to upload to', | ||
| 234 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2020-9280/', | ||
| 235 | 'cve' => 'CVE-2020-9280', | ||
| 236 | ], | ||
| 237 | ], | ||
| 238 | ], | ||
| 239 | 'silverstripe/framework' => [ | ||
| 240 | 'version' => '4.0.0', | ||
| 241 | 'advisories' => [ | ||
| 242 | [ | ||
| 243 | 'title' => 'CVE-2019-12203: Session fixation in "change password" form', | ||
| 244 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2019-12203/', | ||
| 245 | 'cve' => 'CVE-2019-12203', | ||
| 246 | ], | ||
| 247 | [ | ||
| 248 | 'title' => 'CVE-2019-12246: Denial of Service on flush and development URL tools', | ||
| 249 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2019-12246', | ||
| 250 | 'cve' => 'CVE-2019-12246', | ||
| 251 | ], | ||
| 252 | [ | ||
| 253 | 'title' => 'CVE-2019-14272: XSS in file titles managed through the CMS', | ||
| 254 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2019-14272/', | ||
| 255 | 'cve' => 'CVE-2019-14272', | ||
| 256 | ], | ||
| 257 | [ | ||
| 258 | 'title' => 'CVE-2019-14273: Broken Access control on files', | ||
| 259 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2019-14273/', | ||
| 260 | 'cve' => 'CVE-2019-14273', | ||
| 261 | ], | ||
| 262 | [ | ||
| 263 | 'title' => 'CVE-2019-16409: Secureassets and versionedfiles modules can expose versions of ' | ||
| 264 | . 'protected files', | ||
| 265 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2019-16409/', | ||
| 266 | 'cve' => 'CVE-2019-16409', | ||
| 267 | ], | ||
| 268 | [ | ||
| 269 | 'title' => 'CVE-2019-19325: XSS through non-scalar FormField attributes', | ||
| 270 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2019-19325/', | ||
| 271 | 'cve' => 'CVE-2019-19325', | ||
| 272 | ], | ||
| 273 | [ | ||
| 274 | 'title' => 'CVE-2019-19326: Web Cache Poisoning through HTTPRequestBuilder', | ||
| 275 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2019-19326/', | ||
| 276 | 'cve' => 'CVE-2019-19326', | ||
| 277 | ], | ||
| 278 | [ | ||
| 279 | 'title' => 'CVE-2019-5715: Reflected SQL Injection through Form and DataObject', | ||
| 280 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2018-021', | ||
| 281 | 'cve' => 'CVE-2019-5715', | ||
| 282 | ], | ||
| 283 | [ | ||
| 284 | 'title' => 'CVE-2020-26138 FormField: with square brackets in field name skips validation', | ||
| 285 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2020-26138', | ||
| 286 | 'cve' => 'CVE-2020-26138', | ||
| 287 | ], | ||
| 288 | [ | ||
| 289 | 'title' => 'CVE-2020-6164: Information disclosure on /interactive URL path', | ||
| 290 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2020-6164/', | ||
| 291 | 'cve' => 'CVE-2020-6164', | ||
| 292 | ], | ||
| 293 | [ | ||
| 294 | 'title' => 'CVE-2021-25817 XXE: Vulnerability in CSSContentParser', | ||
| 295 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2021-25817', | ||
| 296 | 'cve' => 'CVE-2021-25817', | ||
| 297 | ], | ||
| 298 | [ | ||
| 299 | 'title' => 'SS-2017-007: CSV Excel Macro Injection', | ||
| 300 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2017-007/', | ||
| 301 | 'cve' => null, | ||
| 302 | ], | ||
| 303 | [ | ||
| 304 | 'title' => 'SS-2017-008: SQL injection in full text search of SilverStripe 4', | ||
| 305 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2017-008/', | ||
| 306 | 'cve' => null, | ||
| 307 | ], | ||
| 308 | [ | ||
| 309 | 'title' => 'SS-2017-009: Users inadvertently passing sensitive data to LoginAttempt', | ||
| 310 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2017-009/', | ||
| 311 | 'cve' => null, | ||
| 312 | ], | ||
| 313 | [ | ||
| 314 | 'title' => 'SS-2017-010: install.php discloses sensitive data by pre-populating DB credential ' | ||
| 315 | . 'forms', | ||
| 316 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2017-010/', | ||
| 317 | 'cve' => null, | ||
| 318 | ], | ||
| 319 | [ | ||
| 320 | 'title' => 'SS-2018-001: Privilege Escalation Risk in Member Edit form', | ||
| 321 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2018-001/', | ||
| 322 | 'cve' => null, | ||
| 323 | ], | ||
| 324 | [ | ||
| 325 | 'title' => 'SS-2018-005: isDev and isTest unguarded', | ||
| 326 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2018-005/', | ||
| 327 | 'cve' => null, | ||
| 328 | ], | ||
| 329 | [ | ||
| 330 | 'title' => 'SS-2018-008: BackURL validation bypass with malformed URLs', | ||
| 331 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2018-008/', | ||
| 332 | 'cve' => null, | ||
| 333 | ], | ||
| 334 | [ | ||
| 335 | 'title' => 'SS-2018-010: Member disclosure in login form', | ||
| 336 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2018-010/', | ||
| 337 | 'cve' => null, | ||
| 338 | ], | ||
| 339 | [ | ||
| 340 | 'title' => 'SS-2018-012: Uploaded PHP script execution in assets', | ||
| 341 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2018-012/', | ||
| 342 | 'cve' => null, | ||
| 343 | ], | ||
| 344 | [ | ||
| 345 | 'title' => 'SS-2018-018: Database credentials disclosure during connection failure', | ||
| 346 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2018-018/', | ||
| 347 | 'cve' => null, | ||
| 348 | ], | ||
| 349 | [ | ||
| 350 | 'title' => 'SS-2018-019: Possible denial of service attack vector when flushing', | ||
| 351 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2018-019/', | ||
| 352 | 'cve' => null, | ||
| 353 | ], | ||
| 354 | [ | ||
| 355 | 'title' => 'SS-2018-020: Potential SQL vulnerability in PostgreSQL database connector', | ||
| 356 | 'link' => 'https://www.silverstripe.org/download/security-releases/ss-2018-020/', | ||
| 357 | 'cve' => null, | ||
| 358 | ], | ||
| 359 | ], | ||
| 360 | ], | ||
| 361 | 'symbiote/silverstripe-queuedjobs' => [ | ||
| 362 | 'version' => '4.0.x-dev', | ||
| 363 | 'advisories' => [ | ||
| 364 | [ | ||
| 365 | 'title' => 'CVE-2021-27938: XSS in CreateQueuedJobTask', | ||
| 366 | 'link' => 'https://www.silverstripe.org/download/security-releases/cve-2021-27938', | ||
| 367 | 'cve' => 'CVE-2021-27938', | ||
| 368 | ], | ||
| 369 | ], | ||
| 370 | ] | ||
| 371 | ]; | ||
| 372 | |||
| 373 |         if ($withDev) { | ||
| 374 | $vulnerabilities = array_merge($vulnerabilities, [ | ||
| 375 | 'phpunit/phpunit' => [ | ||
| 376 | 'version' => '5.0.10', | ||
| 377 | 'advisories' => [ | ||
| 378 | [ | ||
| 379 | 'title' => 'RCE vulnerability in phpunit', | ||
| 380 | 'link' => 'https://nvd.nist.gov/vuln/detail/CVE-2017-9841', | ||
| 381 | 'cve' => 'CVE-2017-9841', | ||
| 382 | ], | ||
| 383 | ], | ||
| 384 | ], | ||
| 385 | ]); | ||
| 386 | } | ||
| 387 | return $vulnerabilities; | ||
| 388 | } | ||
| 390 |