Do not use unvalidated request

Metadata

ID: java-security/unvalidated-redirect

Language: Java

Severity: Error

Category: Security

Description

Do not use unvalidated redirect. Always check the redirect URL coming from a request.

Learn More

Non-Compliant Code Examples

public class MyClass {
    protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
        resp.sendRedirect(req.getParameter("redirectUrl"));
    }
}

Compliant Code Examples

public class MyClass {
    protected void doGet(HttpServletRequest req, HttpServletResponse resp) throws ServletException, IOException {
        resp.sendRedirect(validateUrl(req.getParameter("redirectUrl")));
    }
}