flawopen.com/跨站脚本攻击/Java

跨站脚本攻击 in Java

高危 CWE-79 Draft — pending review
Language: English Português (Brasil) Español Français Deutsch Русский 简体中文 日本語 हिन्दी 한국어 Bahasa Indonesia
通俗解释 (ELI5)

Imagine a bulletin board where someone posts an instruction that forces the viewer's computer to secretly send their session cookie to an attacker.

核心概念
output encoding
Converting special markup characters into safe entities so browsers display them as text rather than script.

原理解析

XSS in Java web applications occurs when JSP, Thymeleaf, or FreeMarker templates render request parameters directly into response streams without encoding.

真实安全事件

In 2005, the Samy XSS worm infected over 1 million user profiles on MySpace in under 20 hours, forcing the platform offline.

Documented historical AppSec case study.

缺陷代码 vs 修复方案

VULNERABLE

Welcome, <%= request.getParameter("name") %>
FIXED

Welcome,

修复原理

JSTL and Thymeleaf th:text convert sensitive HTML characters (<, >, &, ") into inert HTML entities.

语言专属陷阱

Thymeleaf th:utext

th:utext explicitly disables escaping. Use th:text for untrusted data.

常见认知误区

"Spring Boot automatically prevents all XSS"

Spring handles URL and JSON encoding, but template rendering depends on proper tag usage.

如何检测与排查

grep -rn "<%=.*getParameter" --include="*.jsp" . grep -rn "th:utext" --include="*.html" .
Scan JSP and template views using FindSecBugs (rule XSS_REQUEST_PARAMETER_TO_JSP_WRITER).

防御自查清单

常见问题 (FAQ)

How should rich user HTML be handled in Java?

Use OWASP Java HTML Sanitizer to strip dangerous tags and attributes before rendering.

参考规范

相关漏洞: SQL Injection Command InjectionPath Traversal