Insecure service configuration
Description
No requestValidationMode is assigned in the server configuration files, which would allow XSS attacks.
Impact
Obtain sensitive information through XSS attacks.
Recommendation
Activate the recommended protection mechanisms as Request validation.
Threat
Anonymous attacker from the Internet.
Expected Remediation Time
⏱️ 60 minutes.
Requirements
185 - Encrypt sensitive information266 - Disable insecure functionalities340 - Use octet stream downloadsRules
Java Escape Model Strings DisabledJava Ignore Comments Set FalseConfig Files Misconfiguration In ImpersonationJava Enabled Extensions DeserializationJson Yaml K8s Use Of Probe HostJson Ssl Port ZeroGithub Protection DisabledGithub Force Push AllowedGithub Code Review Not RequiredGithub Stale Reviews Not DismissedGithub Status Checks Not Required