Win a copy of The Journey To Enterprise Agility this week in the Agile and Other Processes forum! And see the welcome thread for 20% off.
  • Post Reply Bookmark Topic Watch Topic
  • New Topic
programming forums Java Mobile Certification Databases Caching Books Engineering Micro Controllers OS Languages Paradigms IDEs Build Tools Frameworks Application Servers Open Source This Site Careers Other all forums
this forum made possible by our volunteer staff, including ...
  • Jeanne Boyarsky
  • Liutauras Vilda
  • Campbell Ritchie
  • Tim Cooke
  • Bear Bibeault
  • Paul Clapham
  • Junilu Lacar
  • Knute Snortum
Saloon Keepers:
  • Ron McLeod
  • Ganesh Patekar
  • Tim Moores
  • Pete Letkeman
  • Stephan van Hulst
  • Carey Brown
  • Tim Holloway
  • Joe Ess

Fortify complains about The method sends unvalidated data to a web browser  RSS feed

Ranch Hand
Posts: 39
  • Mark post as helpful
  • send pies
  • Quote
  • Report post to moderator
I have a Spring Rest api that gets this fault when fortify is scanning the application
Does anyone knows how to fix this ?
I have tried with @Valid on the object and springs HtmlUtils.

I have also added a filter CrossScriptingFilter in the web.xml which do works, but still fortify complains on this method.

heres the cosde


Here is the utils method

here is my dto

  • Post Reply Bookmark Topic Watch Topic
  • New Topic
Boost this thread!