Skip to content

CX Portability_Flaw_Locale_Dependent_Comparison @ src/main/java/org/joychou/security/SecurityUtil.java [master] #75

@DannyLoweCx

Description

@DannyLoweCx

Portability_Flaw_Locale_Dependent_Comparison issue exists @ src/main/java/org/joychou/security/SecurityUtil.java in branch master

The application handles input strings in a locale-unspecific manner. In particular, src\main\java\org\joychou\security\SecurityUtil.java's checkURLbyEndsWith calls toLowerCase at line 23 to manipulate the string. The resulting string is compared with endsWith by checkURLbyEndsWith, at src\main\java\org\joychou\security\SecurityUtil.java:23.

Severity: Low

CWE:474

Vulnerability details and guidance

Internal Guidance

Checkmarx

Lines: 34


Code (Line #34):

            String host = uri.getHost().toLowerCase();

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions