flightstats / hub

fault tolerant, highly available service for data storage and distribution
http://www.flightstats.com
MIT License
103 stars 35 forks source link

Added Encoder for Channelname in delete method #1365

Closed Haripriya99j closed 5 months ago

Haripriya99j commented 6 months ago

Checkmarx High Vulnerabilities Fix: Added Encoder for channelName user_input in delete method. File: InternalChannelResource.java

lkemmerer commented 5 months ago

Other than adding the owasp library to the build and linking to a build with a passing build and integration tests, this looks good!

mishraa8 commented 5 months ago

Good work @Haripriya99j!! You actually found actual issue causing this vulnerability, which resolved other vulnerabilities as well. Let's follow this other similar vulnerability, if any exist.

Haripriya99j commented 5 months ago

Can you attach successful build job id and checkmarx screen shot.

https://ddt-jenkins.prod.flightstats.io/job/run-hub-development-integration/112/