Uploaded image for project: 'Data Movement as a Platform'
  1. Data Movement as a Platform
  2. DMAAP-1624

[DR] fix CRITICAL cross-site scripting (xss) issues identified in sonarcloud

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Highest Highest
    • Jakarta Release
    • Istanbul Release, Jakarta Release

      Sonarcloud identified the following security bugs in your project and, as agreed by the TSC, should be fixed within the Istanbul release. Any not finished in Istanbul must be fixed within the Jakarta release. Follow each of the URLs for details on each each bug, along with recommended fixes.

      The verification URL for these issues will be https://sonarcloud.io/organizations/onap/issues?id=onap_dmaap-datarouter&resolved=false&sonarsourceSecurity=xss

      If any of the links below fail, please find your code on the master list found at https://sonarcloud.io/organizations/onap/issues?resolved=false&sonarsourceSecurity=xss

      Project: onap_dmaap-datarouter
      Component: onap_dmaap-datarouter:datarouter-node/src/main/java/org/onap/dmaap/datarouter/node/NodeServlet.java
      Message: Change this code to not place user-controlled data in the header.
      Severity: CRITICAL
      Line: 336
      Effort: 30min
      Creation-Date: 2019-02-06T12:44:36+0100
      URL: https://sonarcloud.io/project/issues?id=onap_dmaap-datarouter&open=AW8V3S951zbPcHHqYuq_

            david.mcweeney David McWeeney
            zwarico Amy Zwarico
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: