Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

conforming-agent: Add Schema Validation to Xml/JsonProvider #32

Open
drcgjung opened this issue Aug 31, 2023 · 0 comments
Open

conforming-agent: Add Schema Validation to Xml/JsonProvider #32

drcgjung opened this issue Aug 31, 2023 · 0 comments

Comments

@drcgjung
Copy link
Contributor

Description / As-Is

XML/JsonProvider convert any incoming message/request body into java structures. By knowing the execution environment, an attacker could try to design input structures in order to target the evaluation logic behind.

How it should be

XML/JsonProvider should validate incoming message/request bodies according to a set of allowed schemas. this restricts the opportunities to design arbitrary input structures.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant