Skip to content

CWE-117,93 - Log injection in DatadogAPICallFunction for datadog_integration_api_call_v2.yaml #154

@ycrc5

Description

@ycrc5

Expected Behavior

No vulnerabilities found for Cloudformation lambda

Actual Behavior

Getting vulnerability for CWE-117,93 - Log injection in DatadogAPICallFunction. Using template https://github.com/DataDog/cloudformation-template/blob/master/aws_quickstart/datadog_integration_api_call_v2.yaml .

Steps to Reproduce the Problem

  1. Deploy template https://github.com/DataDog/cloudformation-template/blob/master/aws_quickstart/datadog_integration_api_call_v2.yaml
  2. Use code scanning tools (such as aws inspector)
  3. Check findings.

Specifications

  • Datadog CloudFormation template version: Latest version

Stacktrace

Paste here

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions