cod*_*123 9 java xss spring sanitization checkmarx
我正在使用 Spring MVC,并且我有一个具有 HTTP 方法 Post 的端点。
\n\n@ResponseBody\npublic ResponseEntity<Object> request(@RequestBody @Valid RequestPayload requestBody){\n //Code\n}\n\npublic class RequestPayload {\n\n private String op;\n private Collection<Payload> payload;\n //Getter & Setters\n\n}\n\npublic class Payload implements Serializable {\n private Map<String, Object> properties = new HashMap<>();\n //Getter & Setters\n}\nRun Code Online (Sandbox Code Playgroud)\n\n我使用 JSON Sanitizer 和 Jsoup 将其转换为 JSON,然后使用下面的代码再次转换为 Java 类。
\n\nprivate static final ObjectMapper MAPPER = new ObjectMapper();\npublic static <T> T sanitizeHTML(T requestBody, Class<T> klass) {\n if(Objects.nonNull(requestBody)) {\n try {\n return MAPPER.readValue(Jsoup.clean(MAPPER.writeValueAsString(requestBody), Whitelist.none()), klass);\n } catch (IOException e) {\n LOGGER.error("Exception occurred while removing XSS texts = {} ", e);\n }\n }\n return requestBody;\n}\nRun Code Online (Sandbox Code Playgroud)\n\n我也尝试过使用 Esapi & Json Sanitizer。对于请求参数和标头,我在下面使用它并且工作正常。
\n\npublic static String sanitizeHTML(String value) {\n return StringEscapeUtils.escapeHtml(value);\n}\nRun Code Online (Sandbox Code Playgroud)\n\n您能否建议使用什么来清理 Post Request 或 Pojo。
\n\n我从 CheckMarx 收到以下错误
\n\n"Method\xc2\xa0request\xc2\xa0at line\xc2\xa0l1\xc2\xa0of\xc2\xa0Class C1\xc2\xa0gets user input for the\xc2\xa0requestBody\xc2\xa0element. This element\xe2\x80\x99s value then flows through the code without being properly sanitized or validated and is eventually displayed to the user in method\xc2\xa0request line\xc2\xa0161\xc2\xa0of\xc2\xa0Class C1. This may enable a Cross-Site-Scripting attack."\nRun Code Online (Sandbox Code Playgroud)\n
| 归档时间: |
|
| 查看次数: |
3425 次 |
| 最近记录: |