Java: queries about user-controlled URLs should be sanitized by enforcing a prefix
Đang mở
Java
question
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 141
Mô tả
This comes from a discussion with @smowton over [here](https://github.com/github/securitylab-bounties/issues/92).
Certain categories such as Open Redirect, SSRF and Android WebView URL injection will benefit from a sanitizer which would clean the taint in case the dataflow goes through a string prefix operation (concatenation, format strings, string buffers, string writer ...). Since not controlling the begging of the URL will severely decrease the exploitability of these issues.
Hướng dẫn đóng góp
Đánh giá
Issue này chưa được đánh giá.