[Cycode] Fix for SAST detections - Unsanitized external input in SQL query#8
Open
cycode-security[bot] wants to merge 1 commit into
Open
[Cycode] Fix for SAST detections - Unsanitized external input in SQL query#8cycode-security[bot] wants to merge 1 commit into
cycode-security[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
[Cycode] Fix for SAST detections - Unsanitized external input in SQL query
Code explainer
The vulnerability in this code is an SQL injection risk caused by directly concatenating unsanitized user input (
nameandauth_tanparameters) into SQL queries. This occurs on line62where the query string is constructed by directly embedding the parameters:"SELECT * FROM employees WHERE last_name = '" + name + "' AND auth_tan = '" + auth_tan + "'". This allows attackers to manipulate the SQL query structure by injecting malicious SQL code through these parameters, potentially accessing unauthorized data or performing destructive operations.The fix replaces direct string concatenation with parameterized queries using PreparedStatement. This approach ensures that user input is treated as data rather than executable SQL code. The PreparedStatement automatically handles proper escaping and quoting of parameters, preventing SQL injection attacks. The same security principle is applied to the logging function to maintain consistent security practices throughout the codebase.
Remediation Instructions