Unsanitized user input in logger message
Overview
Description
Remediation Guidelines
String username = request.getParameter("username"); log.warn("Username is " + username); // unsafeString username = sanitized(request.getParameter("username")); log.warn("Username is" + username);
References
Configuration
Last updated