
PBarry205203 (Community Member) asked a question.
Hi,
I was expecting that writing out JSP values in HTML response would not longer report CEW ID 80 once I encoded them using Apache Common Langs org.apache.commons.lang3.StringEscapeUtils.escapeXml11(..) method
It still reporting as an issue however.
<tr>
<td>https.nonProxyHosts</td>
<td><input name="httpsNonProxyHosts" type="text" size="132" value="<%=StringEscapeUtils.escapeXml11(httpsNonProxyHosts)%>"/></td>
</tr>
.png)
Hi @PBarry205203 (Community Member) ,
Veracode Static Analysis does not support the deprecated method org.apache.commons.lang3.StringEscapeUtils.escapeXml11 as a Supported Cleansing Function.
We recommend using a Supported Cleansing Function like org.owasp.encoder.Encode.forHtmlAttribute, or another appropriate function from our list of Supported Cleansing Functions: https://help.veracode.com/go/review_cleansers .
Thank you,
Boy Baukema