Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Logging unsanitized user input can also result in leaking sensitive data across a trust boundary, or storing sensitive data in a manner that is contrary to local law or regulation. See rule IDS01IDS00-J. Sanitize untrusted data passed across a trust boundary for more details on input sanitization.

...

This compliant solution sanitizes the user name input before logging it. Refer to rule IDS01IDS00-J. Sanitize untrusted data passed across a trust boundary for more details on input sanitization.

...

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="3fd7a61fc72ae212-bf0c8644-4f5c4d72-89058cbb-b4160dd51ec879a13125c227"><ac:plain-text-body><![CDATA[

[[MITRE 2009

AA. Bibliography#MITRE 09]]

[CWE ID 144

http://cwe.mitre.org/data/definitions/144.html] "Improper Neutralization of Line Delimiters"

]]></ac:plain-text-body></ac:structured-macro>

 

CWE ID 150 "Improper Neutralization of Escape, Meta, or Control Sequences"

...

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="97433ccd7132475d-277f98c2-4a1e4a8f-b3e48c55-ba4071671be2dc98aee31d14"><ac:plain-text-body><![CDATA[

[[API 2006

AA. Bibliography#API 06]]

]]></ac:plain-text-body></ac:structured-macro>

...