Description
There are several points where user injected data is used to build paths, run SQL queries, or read data and adequate protections are not provided. These users should have a degree of trust before having access to the system in many use cases, but these gaps should be fixed when possible.
See
https://sonarcloud.io/project/issues?open=AZSvBa3GbISw8Cyr7KIl&id=NASA-AMMOS_common-workflow-service
https://sonarcloud.io/project/issues?open=AZSvBbRVbISw8Cyr7K8x&id=NASA-AMMOS_common-workflow-service
https://sonarcloud.io/project/issues?open=AZSvBbRVbISw8Cyr7K8r&id=NASA-AMMOS_common-workflow-service
https://sonarcloud.io/project/issues?open=AZSvBbRVbISw8Cyr7K8s&id=NASA-AMMOS_common-workflow-service
https://sonarcloud.io/project/issues?open=AZSvBbRVbISw8Cyr7K8v&id=NASA-AMMOS_common-workflow-service
https://sonarcloud.io/project/issues?open=AZSvBbRVbISw8Cyr7K8t&id=NASA-AMMOS_common-workflow-service
https://sonarcloud.io/project/issues?open=AZSvBbRVbISw8Cyr7K8u&id=NASA-AMMOS_common-workflow-service
https://sonarcloud.io/project/issues?open=AZSvBbRVbISw8Cyr7K8y&id=NASA-AMMOS_common-workflow-service
https://sonarcloud.io/project/issues?open=AZSvBbQubISw8Cyr7K4Q&id=NASA-AMMOS_common-workflow-service
https://sonarcloud.io/project/issues?open=AZSvBbSdbISw8Cyr7K-I&id=NASA-AMMOS_common-workflow-service
https://sonarcloud.io/project/issues?open=AZSvBbSdbISw8Cyr7K-J&id=NASA-AMMOS_common-workflow-service