﻿# V5342\. OWASP\. Potentially tainted data is stored in an object that can be used as a source of trusted data\.

The analyzer has detected that unverified data is passed to an object that could be used as a source of trusted data in another part of the program\. This violates the trust boundary between an untrusted source and a component that treats the data as trusted\. 

This vulnerability can be categorized under the OWASP Top 10 as follows: 

* [A06:2025 Insecure Design](https://owasp.org/Top10/2025/A06_2025-Insecure_Design/)
* [A04:2021 – Insecure Design](https://owasp.org/Top10/2021/A04_2021-Insecure_Design/)

The example:

```cpp
public void configure(HttpSession session, HttpServletRequest request) {
  var arg = request.getParameter("arg");
  session.setAttribute("session_attribute", arg); // <=
}
```

An argument passed in a user request is stored in a session attribute \(an area of trusted data\) without any validation\. The severity of this trust boundary violation depends on how the stored value is subsequently used\. For example, if it is used when constructing a database query, this could lead to an SQL injection\. 

To fix this vulnerability, verify all external arguments to ensure they are allowed\.

```cpp
public Set<String> ALLOWED = ....

public void configure(HttpSession session, HttpServletRequest request) {
  var arg = request.getParameter("arg");
  if (ALLOWED.contains(arg)) {
    session.setAttribute("session_attribute", arg);
  }
}
```