关注JEECG发展历程 关注最新动态和版本, 记录JEECG成长点滴 更新日志 - 技术支持 - 招聘英才

JEECG最新版本下载 JEECG智能开发平台 - 显著提高开发效率 常见问题 - 入门视频 - 参与开源团队

商务QQ: 69893005、3102411850 商务热线(5*8小时): 010-64808099 官方邮箱: jeecgos@163.com

查看: 5932|回复: 0

HTTP请求参数绑定到User所有属性

[复制链接]
发表于 2021-12-8 18:28:48 | 显示全部楼层 |阅读模式
奇安信代码卫生检查 为中等级缺陷 不安全的框架绑定 只是部分检查截图:
  
缺陷7
  
爆发行:java/com/interesting/business/system/controller/SysAnnouncementController.java;81行
跟踪路径1:
  
1   e_zhiyou/interesting-business-center/interesting-business-center-system/src/main/java/com/interesting/business/system/controller/SysAnnouncementController.java;81行queryPageList



  
缺陷21
  
爆发行:java/com/interesting/business/system/controller/SysUserController.java;700行
跟踪路径1:
  
1   e_zhiyou/interesting-business-center/interesting-business-center-system/src/main/java/com/interesting/business/system/controller/SysUserController.java;700行queryByDepartId
缺陷22
爆发行:java/com/interesting/modules/demo/controller/TaskInfoController.java;155行
跟踪路径1:
  
1  e_zhiyou/interesting-business-center/interesting-business-center-ezhiyou/src/main/java/com/interesting/modules/demo/controller/TaskInfoController.java;155行exportXls
缺陷23
爆发行:java/com/interesting/business/system/controller/SysUserController.java;949行
跟踪路径1:
  
1   e_zhiyou/interesting-business-center/interesting-business-center-system/src/main/java/com/interesting/business/system/controller/SysUserController.java;949行querySysUser
缺陷24
爆发行:java/com/interesting/business/system/controller/ThirdLoginController.java;251行
跟踪路径1:
  
1  e_zhiyou/interesting-business-center/interesting-business-center-system/src/main/java/com/interesting/business/system/controller/ThirdLoginController.java;251行bindingThirdPhone
  
缺陷10
  
  
爆发行:java/com/interesting/business/system/controller/SysUserAgentController.java;71行
  
  
跟踪路径1:
  
1  e_zhiyou/interesting-business-center/interesting-business-center-system/src/main/java/com/interesting/business/system/controller/SysUserAgentController.java;71行queryPageList
  




您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表