Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Logging unsanitized user input can also result in leaking sensitive data across a trust boundary, or storing sensitive data in a manner that is contrary to local law or regulation. See rule IDS01IDS00-J. Sanitize untrusted data passed across a trust boundary for more details on input sanitization.

...

This compliant solution sanitizes the user name input before logging it. Refer to rule IDS01IDS00-J. Sanitize untrusted data passed across a trust boundary for more details on input sanitization.

...

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="dceac8dd730a3bba-a17bdaa1-4dc64984-8e2c98e0-718cbe124aff307eefdd84ca"><ac:plain-text-body><![CDATA[

[[MITRE 2009

AA. Bibliography#MITRE 09]]

[CWE ID 144

http://cwe.mitre.org/data/definitions/144.html] "Improper Neutralization of Line Delimiters"

]]></ac:plain-text-body></ac:structured-macro>

 

CWE ID 150 "Improper Neutralization of Escape, Meta, or Control Sequences"

...

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="95484f08a8006fb6-5ce4554a-473a424a-919bbf43-a97d8f7967f8d287d07c761a"><ac:plain-text-body><![CDATA[

[[API 2006

AA. Bibliography#API 06]]

]]></ac:plain-text-body></ac:structured-macro>

...