We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 66d7cab commit 1fe57aaCopy full SHA for 1fe57aa
1 file changed
src/java/detectors/unrestricted_file_upload/UnrestrictedFileUpload.java
@@ -12,11 +12,14 @@
12
import java.util.HashMap;
13
import org.springframework.util.StringUtils;
14
import javax.servlet.ServletException;
15
+import javax.servlet.http.Part;
16
+import java.nio.file.Files;
17
+import java.nio.file.StandardCopyOption;
18
19
public class UnrestrictedFileUpload {
20
21
// {fact rule=unrestricted-file-upload@v1.0 defects=1}
- public void unrestrictedFileUploadNoncompliant(HttpServletRequest request) {
22
+ public void unrestrictedFileUploadNoncompliant(HttpServletRequest request, HttpServletResponse response) {
23
Part filePart = request.getPart("fileToUpload");
24
InputStream fileInputStream = filePart.getInputStream();
25
// Noncompliant: the uploaded file can have any extension.
0 commit comments