wwesleyalves / WebGoat2

Other
0 stars 0 forks source link

CX Deserialization_of_Untrusted_Data @ webgoat-lessons/vulnerable-components/src/main/java/org/owasp/webgoat/vulnerable_components/VulnerableComponentsLesson.java [main] #13

Open wwesleyalves opened 1 year ago

wwesleyalves commented 1 year ago

Deserialization_of_Untrusted_Data issue exists @ webgoat-lessons/vulnerable-components/src/main/java/org/owasp/webgoat/vulnerable_components/VulnerableComponentsLesson.java in branch main

The serialized object payload processed in completed in the file webgoat-lessons\vulnerable-components\src\main\java\org\owasp\webgoat\vulnerable_components\VulnerableComponentsLesson.java at line 41 is deserialized by fromXML in the file webgoat-lessons\vulnerable-components\src\main\java\org\owasp\webgoat\vulnerable_components\VulnerableComponentsLesson.java at line 52.Similarity ID: -999209152

Severity: High

CWE:502

Vulnerability details and guidance

Checkmarx

Training Recommended Fix

Lines: 41


Code (Line #41):

AttackResult completed(@RequestParam String payload) {

wwesleyalves commented 1 year ago

Issue still exists.

wwesleyalves commented 1 year ago

Issue still exists.

wwesleyalves commented 1 year ago

Issue still exists.

wwesleyalves commented 1 year ago

Issue still exists.