rspec/rules/S5304/java/rule.adoc
2021-04-28 16:49:39 +02:00

18 lines
471 B
Plaintext

== Sensitive Code Example
----
public class Main {
public static void main (String[] args) {
System.getenv(); // Sensitive
System.getenv("myvar"); // Sensitive
ProcessBuilder processBuilder = new ProcessBuilder();
Map<String, String> environment = processBuilder.environment(); // Sensitive
environment.put("VAR", "value");
Runtime.getRuntime().exec("ping", new String[]{"env=val"}); // Sensitive
}
}
----