I am having trouble figuring out a solution to a problen HP Fortify SCA is reporting. The issue it reports is:
Hardcoded passwords may compromise system security in a way that cannot be easily remedied.
The code looks similar to this:
@Configuration
public class MySpringConfig {
private final String userName;
private final String password;
@Autowired
public MySpringConfig(
@Value("${my.userName}") final String userName,
@Value("${my.password}") final String password) {
this.host = host;
this.userName = userName;
this.password = password;
}
...
}
I cannot understand why Fortify would think this is a hard coded password. The password is being passed as a parameter to the constructor, and it is coming from a Spring @Value.
I have considered using @FortifyNotPassword to stop this false positive, but this is actually a password. I'd rather not use that annotation because it could then miss real issues, like logging this field's value.