The analyzer has detected that unverified data is passed to an object that could be used as a source of trusted data in another part of the program. This violates the trust boundary between an untrusted source and a component that treats the data as trusted.
This vulnerability can be categorized under the OWASP Top 10 as follows:
The example:
public void configure(HttpSession session, HttpServletRequest request) {
var arg = request.getParameter("arg");
session.setAttribute("session_attribute", arg); // <=
}
An argument passed in a user request is stored in a session attribute (an area of trusted data) without any validation. The severity of this trust boundary violation depends on how the stored value is subsequently used. For example, if it is used when constructing a database query, this could lead to an SQL injection.
To fix this vulnerability, verify all external arguments to ensure they are allowed.
public Set<String> ALLOWED = ....
public void configure(HttpSession session, HttpServletRequest request) {
var arg = request.getParameter("arg");
if (ALLOWED.contains(arg)) {
session.setAttribute("session_attribute", arg);
}
}
This diagnostic rule is classified as:
|
Was this page helpful?
Your message has been sent. We will email you at
If you do not see the email in your inbox, please check if it is filtered to one of the following folders: