PBarry205203 (Community Member) asked a question.

CWE ID 80 still reporting after using Apache org.apache.commons.lang3.StringEscapeUtils

Hi,

I was expecting that writing out JSP values in HTML response would not longer report CEW ID 80 once I encoded them using Apache Common Langs org.apache.commons.lang3.StringEscapeUtils.escapeXml11(..) method

 

It still reporting as an issue however.

 

<tr>

<td>https.nonProxyHosts</td>

<td><input name="httpsNonProxyHosts" type="text" size="132" value="<%=StringEscapeUtils.escapeXml11(httpsNonProxyHosts)%>"/></td>

</tr>


VCode likes this.
  • Hi @PBarry205203 (Community Member)​ ,

     

    Veracode Static Analysis does not support the deprecated method org.apache.commons.lang3.StringEscapeUtils.escapeXml11 as a Supported Cleansing Function.

    We recommend using a Supported Cleansing Function like org.owasp.encoder.Encode.forHtmlAttribute, or another appropriate function from our list of Supported Cleansing Functions: https://help.veracode.com/go/review_cleansers .

     

    Thank you,

    Boy Baukema

    Expand Post

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.