在Veracode报告中,我在一些java文件中得到了错误CWE 93。在静态扫描的例子中,一些代码是
MimeMessage msg = new MimeMessage(session); msg.setFrom(new InternetAddress(msmtpfrom));2.msg.setRecipients(Message.RecipientType.TO, address);
我该怎么解决?
提前谢谢
发布于 2019-04-16 11:23:10
只需用空字符串("")替换出现在字符串变量(如msmtpfrom,address )中的CRLF。看看有相关答案的类似问题:How to fix "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')"
https://stackoverflow.com/questions/55705738
复制相似问题