如何解决Checkmarx检测出的Unsafe_Use_Of_Target_blank漏洞?
Unsafe_Use_Of_Target_blank Vulnerabilities in UI5 Hey there! Let's tackle those Unsafe_Use_Of_Target_blank issues flagged by Checkmarx in your UI5 project. This vulnerability comes from using window.open() without critical security attributes, which leaves your app open to tabnabbing attacks—where malicious sites can hijack the opened tab and impersonate your app. Here's how to fix each of your code lines:
1. First code line fix
Original code:
window.open(new URL(sCustomUrl).origin + "/" + sParam);
Fixed code:
const targetUrl = new URL(sCustomUrl).origin + "/" + sParam; const newWindow = window.open(targetUrl, '_blank', 'noopener,noreferrer');
Why this works:
noopenerblocks the newly opened window from accessing your original app'swindow.openerobject, which is the core vector for tabnabbing.noreferrerprevents the referrer header from being sent to the target site, adding an extra layer of privacy and reducing information leakage.
2. Second code line fix
Original code:
window.open(sCustomUrl + this.getView().getModel().getProperty("/ID"));
Fixed code:
const targetUrl = sCustomUrl + this.getView().getModel().getProperty("/ID"); const newWindow = window.open(targetUrl, '_blank', 'noopener,noreferrer');
Why this works:
Even if sCustomUrl points to an internal trusted resource, adding these attributes ensures that if the URL ever changes to an external source later, your app remains protected. It's a proactive security measure that follows industry best practices.
3. Third code line fix
Original code:
window.open(this.urlToID);
Fixed code:
const newWindow = window.open(this.urlToID, '_blank', 'noopener,noreferrer');
Why this works:
Same security principles apply here. By explicitly setting these attributes, you eliminate any risk of the opened tab being controlled by a malicious actor, regardless of where this.urlToID points.
Bonus: UI5-specific alternative
If your use case allows, consider using SAP UI5's built-in sap.m.URLHelper.redirect() method. It handles security best practices (like adding noopener/noreferrer) internally, so you don't have to manually set them:
sap.m.URLHelper.redirect(this.urlToID, true); // The second parameter `true` opens in a new tab
内容的提问来源于stack exchange,提问作者Geo Joseph

