Skip to content

use DTO JavaEE design pattern to access webapp objects with API #2917

Open
@QiAnXinCodeSafe

Description

@QiAnXinCodeSafe

opengrok-master/opengrok-web/src/main/java/org/opengrok/web/api/v1/controller/ProjectsController.java
image

opengrok-master/opengrok-indexer/src/main/java/org/opengrok/indexer/util/ClassUtil.java
image
image

The method writes unvalidated input into JSON. This call could allow an attacker to inject arbitrary elements or attributes into the JSON entity.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions