Lack of data validation - Trust boundary violation
Description
The system mixes trusted and untrusted data in the same data structure or structured message.
Impact
Introduce data into critical data structures, which could lead to some types of injections.
Recommendation
- Prevent the use of untrusted data in critical data structures or structured messages.
Threat
Authenticated attacker from the Internet.
Expected Remediation Time
⏱️ 45 minutes.
Requirements
173 - Discard unsafe inputs320 - Avoid client-side control enforcement342 - Validate request parametersRules
Java Trust Boundary ViolationPython Flask Uncontrolled Format StringPython Django Uncontrolled Format StringPython Tornado Uncontrolled Format StringKotlin Inclusion Of Insecure FunctionalityPython Fastapi Uncontrolled Format StringPhp Session Trust Boundary ViolationPython Starlette Uncontrolled Format StringScala Inclusion Insecure Functionality