jbruinaud / WebGoatNet

WebGoat .Net for demos
0 stars 0 forks source link

CX Heap_Inspection @ App_Code/CustomerLoginData.cs [master] #195

Open jbruinaud opened 4 years ago

jbruinaud commented 4 years ago

Heap_Inspection issue exists @ App_Code/CustomerLoginData.cs in branch master

Method string.Empty; at line 11 of App_Code\CustomerLoginData.cs defines password, which is designated to contain user passwords. However, while plaintext passwords are later assigned to password, this variable is never cleared from memory. 

Severity: Medium

CWE:244

Checkmarx

Lines: 11


Code (Line #11):

        public string password = string.Empty;