X-Forward-For和接受语言字段是否可以用于日志锻造?
我的Javaee代码由Fortify SCA扫描,报告说我的HttpservletRequest .getLocale()()和httpservletrequest.getheader(“ X-Forward-For”)可能会导致日志锻造。根据我的知识,GetLocale()将其数据仅限于语言环境类型,而X-Forward-For的字段只能放置IP。因此,他们不可能引起任何“日志锻造”。
所以我想问它们实际上可以用于锻造吗?还是这只是另一个强化的低端程序员“思考”它会?
I have my JavaEE code scanned by Fortify SCA, it have reported that my httpServletRequest .getLocale() and httpservletRequest.getHeader("X-forward-for") could cause log forging. Based on my knowledge, getLocale() would limit its data to locale type only, and X-forward-for field could only put IP. So there is NO WAY they could cause any "Log forging".
So I'd like to ask will they actually could be used for log forging? or this is just another Fortify's low-end programmer "think" it would?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论