flawopen.com/Cross-Site Scripting/Java

Cross-Site Scripting in Java

Élevée CWE-79 Draft — pending review
Language: English Português (Brasil) Español Français Deutsch Русский 简体中文 日本語 हिन्दी 한국어 Bahasa Indonesia
Explication simple

Imagine a bulletin board where someone posts an instruction that forces the viewer's computer to secretly send their session cookie to an attacker.

Termes clés sur cette page
output encoding
Converting special markup characters into safe entities so browsers display them as text rather than script.

Ce qui se passe

XSS in Java web applications occurs when JSP, Thymeleaf, or FreeMarker templates render request parameters directly into response streams without encoding.

Impact dans le monde réel

In 2005, the Samy XSS worm infected over 1 million user profiles on MySpace in under 20 hours, forcing the platform offline.

Documented historical AppSec case study.

Vulnérable vs corrigé

VULNERABLE

Welcome, <%= request.getParameter("name") %>
FIXED

Welcome,

Pourquoi la correction fonctionne

JSTL and Thymeleaf th:text convert sensitive HTML characters (<, >, &, ") into inert HTML entities.

Pièges spécifiques au langage

Thymeleaf th:utext

th:utext explicitly disables escaping. Use th:text for untrusted data.

Idées reçues courantes

"Spring Boot automatically prevents all XSS"

Spring handles URL and JSON encoding, but template rendering depends on proper tag usage.

Comment vérifier si vous êtes concerné

grep -rn "<%=.*getParameter" --include="*.jsp" . grep -rn "th:utext" --include="*.html" .
Scan JSP and template views using FindSecBugs (rule XSS_REQUEST_PARAMETER_TO_JSP_WRITER).

Liste de contrôle de prévention

Foire aux questions

How should rich user HTML be handled in Java?

Use OWASP Java HTML Sanitizer to strip dangerous tags and attributes before rendering.

Références

Voir aussi : SQL Injection Command InjectionPath Traversal