Fortify Code Scanning: Mass Assignment: Insecure Binder Configuration Vulnerability Solutions

The vulnerability is caused by Controller General of the object as a parameter

solution:

Add the following code Controller class:

    @InitBinder()
    public void initBinder(WebDataBinder binder) {
        binder.setDisallowedFields(new String[]{});
    }

reference:

https://stackoverflow.com/questions/47945383/how-to-fix-mass-assignment-insecure-binder-configuration-api-abuse-structural/48625284#48625284

https://blog.csdn.net/zengxianxue/article/details/78567544

Published 95 original articles · won praise 43 · views 70000 +

Guess you like

Origin blog.csdn.net/lyxuefeng/article/details/103781349