...
Having a public static final array is a potential security risk because the array elements may be modified by a client.
| Rule | Severity | Likelihood | Detectable | RepairableRemediation Cost | Priority | Level |
|---|---|---|---|---|---|---|
OBJ13-J | Medium | Likely | Yes | NoLow | P18P12 | L1 |
Automated Detection
| Tool | Version | Checker | Description | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Parasoft Jtest |
| CERT.OBJ13.RMO | Avoid referencing mutable fields | ||||||
| SonarQube |
| ||||||||
| SpotBugs |
| MS_EXPOSE_REP | Implemented (since 4.3.0) |
...