Our website uses cookies to enhance your browsing experience.
Accept
to the top
>
>
>
V5342. OWASP. Potentially tainted...
menu mobile close menu
Analyzing projects
Additional information
toggle menu Contents

V5342. OWASP. Potentially tainted data is stored in an object that can be used as a source of trusted data.

Sep 29 2026

The analyzer has detected that unverified data is passed to an object that could be used as a source of trusted data in another part of the program. This violates the trust boundary between an untrusted source and a component that treats the data as trusted.

This vulnerability can be categorized under the OWASP Top 10 as follows:

The example:

public void configure(HttpSession session, HttpServletRequest request) {
  var arg = request.getParameter("arg");
  session.setAttribute("session_attribute", arg); // <=
}

An argument passed in a user request is stored in a session attribute (an area of trusted data) without any validation. The severity of this trust boundary violation depends on how the stored value is subsequently used. For example, if it is used when constructing a database query, this could lead to an SQL injection.

To fix this vulnerability, verify all external arguments to ensure they are allowed.

public Set<String> ALLOWED = ....

public void configure(HttpSession session, HttpServletRequest request) {
  var arg = request.getParameter("arg");
  if (ALLOWED.contains(arg)) {
    session.setAttribute("session_attribute", arg);
  }
}

This diagnostic rule is classified as: