You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决Checkmarx检测出的Unsafe_Use_Of_Target_blank漏洞?

Fixing Unsafe_Use_Of_Target_blank Vulnerabilities in UI5

Hey there! Let's tackle those Unsafe_Use_Of_Target_blank issues flagged by Checkmarx in your UI5 project. This vulnerability comes from using window.open() without critical security attributes, which leaves your app open to tabnabbing attacks—where malicious sites can hijack the opened tab and impersonate your app. Here's how to fix each of your code lines:

1. First code line fix

Original code:

window.open(new URL(sCustomUrl).origin + "/" + sParam);

Fixed code:

const targetUrl = new URL(sCustomUrl).origin + "/" + sParam;
const newWindow = window.open(targetUrl, '_blank', 'noopener,noreferrer');

Why this works:

  • noopener blocks the newly opened window from accessing your original app's window.opener object, which is the core vector for tabnabbing.
  • noreferrer prevents the referrer header from being sent to the target site, adding an extra layer of privacy and reducing information leakage.

2. Second code line fix

Original code:

window.open(sCustomUrl + this.getView().getModel().getProperty("/ID"));

Fixed code:

const targetUrl = sCustomUrl + this.getView().getModel().getProperty("/ID");
const newWindow = window.open(targetUrl, '_blank', 'noopener,noreferrer');

Why this works:
Even if sCustomUrl points to an internal trusted resource, adding these attributes ensures that if the URL ever changes to an external source later, your app remains protected. It's a proactive security measure that follows industry best practices.

3. Third code line fix

Original code:

window.open(this.urlToID);

Fixed code:

const newWindow = window.open(this.urlToID, '_blank', 'noopener,noreferrer');

Why this works:
Same security principles apply here. By explicitly setting these attributes, you eliminate any risk of the opened tab being controlled by a malicious actor, regardless of where this.urlToID points.

Bonus: UI5-specific alternative

If your use case allows, consider using SAP UI5's built-in sap.m.URLHelper.redirect() method. It handles security best practices (like adding noopener/noreferrer) internally, so you don't have to manually set them:

sap.m.URLHelper.redirect(this.urlToID, true); // The second parameter `true` opens in a new tab

内容的提问来源于stack exchange,提问作者Geo Joseph

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 20:24:09