validate icon indicating copy to clipboard operation
validate copied to clipboard

Check for special characters in input file strings to avoid vulnerability

Open jordanpadams opened this issue 5 years ago • 0 comments

preparation/core/src/main/java/gov/nasa/pds/tools/label/LabelValidator.java 855 Local-user-controlled data in path expression (CWE-022) Local-user-controlled data in path expression (CWE-022).  Accessing paths influenced by users can allow an attacker to access unexpected resources. Y Chould check these URLs are not some URL exploit.   3 CWE-022 Test variable ”new File(args[0])” to ensure no special characters before being opened potential redirect vulnerability.
preparation/core/src/main/java/gov/nasa/pds/tools/util/VersionInfo.java 74 Local-user-controlled data in path expression (CWE-022) Local-user-controlled data in path expression (CWE-022).  Accessing paths influenced by users can allow an attacker to access unexpected resources. Y Chould check these URLs are not some URL exploit.   3 CWE-022 Test variable ”schemaDirString” to ensure no special characters before being opened potential redirect vulnerability.

jordanpadams avatar Oct 17 '19 08:10 jordanpadams