如何在 Http Post 中清理和验证 Pojo 以通过 Checkmarx 扫描

cod*_*123 9 java xss spring sanitization checkmarx

我正在使用 Spring MVC,并且我有一个具有 HTTP 方法 Post 的端点。

\n\n
@ResponseBody\npublic ResponseEntity<Object> request(@RequestBody @Valid RequestPayload requestBody){\n //Code\n}\n\npublic class RequestPayload {\n\n    private String op;\n    private Collection<Payload> payload;\n    //Getter & Setters\n\n}\n\npublic class Payload implements Serializable {\n    private Map<String, Object> properties = new HashMap<>();\n    //Getter & Setters\n}\n
Run Code Online (Sandbox Code Playgroud)\n\n

我使用 JSON Sanitizer 和 Jsoup 将其转换为 JSON,然后使用下面的代码再次转换为 Java 类。

\n\n
private static final ObjectMapper MAPPER = new ObjectMapper();\npublic static <T> T sanitizeHTML(T requestBody, Class<T> klass) {\n    if(Objects.nonNull(requestBody)) {\n        try {\n            return MAPPER.readValue(Jsoup.clean(MAPPER.writeValueAsString(requestBody), Whitelist.none()), klass);\n        } catch (IOException e) {\n            LOGGER.error("Exception occurred while removing XSS texts = {} ", e);\n        }\n    }\n    return requestBody;\n}\n
Run Code Online (Sandbox Code Playgroud)\n\n

我也尝试过使用 Esapi & Json Sanitizer。对于请求参数和标头,我在下面使用它并且工作正常。

\n\n
public static String sanitizeHTML(String value) {\n    return StringEscapeUtils.escapeHtml(value);\n}\n
Run Code Online (Sandbox Code Playgroud)\n\n

您能否建议使用什么来清理 Post Request 或 Pojo。

\n\n

我从 CheckMarx 收到以下错误

\n\n
"Method\xc2\xa0request\xc2\xa0at line\xc2\xa0l1\xc2\xa0of\xc2\xa0Class C1\xc2\xa0gets user input for the\xc2\xa0requestBody\xc2\xa0element. This element\xe2\x80\x99s value then flows through the code without being properly sanitized or validated and is eventually displayed to the user in method\xc2\xa0request line\xc2\xa0161\xc2\xa0of\xc2\xa0Class C1. This may enable a Cross-Site-Scripting attack."\n
Run Code Online (Sandbox Code Playgroud)\n