rspec/rules/S4434/java/rule.adoc

23 lines
492 B
Plaintext
Raw Normal View History

== Sensitive Code Example
----
DirContext ctx = new InitialDirContext();
// ...
ctx.search(query, filter,
new SearchControls(scope, countLimit, timeLimit, attributes,
true, // Noncompliant; allows deserialization
deref));
----
== Compliant Solution
----
DirContext ctx = new InitialDirContext();
// ...
ctx.search(query, filter,
new SearchControls(scope, countLimit, timeLimit, attributes,
false, // Compliant
deref));
----