You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于spring-security-webauthn.js中Veracode检测CWE误报的技术咨询

Veracode扫描误报的代码修改合理性验证请求

在对公司项目进行漏洞扫描时,Veracode检测到spring-security-webauthn.js第199行存在以下两个漏洞告警:

  • CWE-80:网页中脚本相关HTML标签未正确中和
  • CWE-601:URL重定向至不可信站点

我尝试将重定向逻辑改为内联实现(不创建中间变量),使其不再匹配SAST扫描规则,从而通过检测。具体修改对象是authenticateOrError函数:

修改前代码

async function authenticateOrError(headers, contextPath, useConditionalMediation) {
  try {
    const redirectUrl = await webauthn.authenticate(headers, contextPath, useConditionalMediation);
    window.location.href = redirectUrl;
  } catch (err) {
    console.error(err);
    window.location.href = `${contextPath}/login?error`;
  }
}

修改后代码

async function authenticateOrError(headers, contextPath, useConditionalMediation) {
  try {
    window.location.href = await webauthn.authenticate(headers, contextPath, useConditionalMediation);
  } catch (err) {
    console.error(err);
    window.location.href = `${contextPath}/login?error`;
  }
}

我认为原代码本身并无安全危害,本次修改未改变函数功能,仅用于消除扫描误报。现需验证该修改的合理性,诚邀各位提供意见与反馈。

内容的提问来源于stack exchange,提问作者mototim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 22:02:08