rspec/rules/S2574/rule-except-see.adoc
2022-02-04 16:28:24 +00:00

18 lines
409 B
Plaintext

Using unvalidated values can expose an application to injection attacks.
== Noncompliant Code Example
[source,text]
----
public void doPost(HttpServletRequest request, HttpServletResponse response) throws IOException, ServletException {
// ...
Employee employee = new Employee();
employee.setFirstName(request.getParameter("firstName")); // Noncompliant
// ...
save(employee); // Uh-oh!
----