Fortify Scan Issue : Cross-Site Scripting: Persistent (Input Validation and Representation, Data Flow)

Viewed 2064

I have implemented rest api with all the CURD operations. when i run fortify scan, it shows cross-site scripting issue for all the CURD operation methods in controller. I don't have a web layer in my project. we are providing rest service for the consumer. I have tried multiple things online nothing works. Is their any way to fix this issues other than adding validation for the input and output data? Here is the code for GET :

@RequestMapping(value = "/", method = {RequestMethod.GET}, headers = "Accept=application/json")
public ResponseEntity<List<Object>> getRecords(
    @RequestParam(value = "firstName", required = false) String firstName,
    @RequestParam(value = "lastName", required = false) String lastName,
    @RequestParam(value = "city", required = false) String city,
    @RequestHeader(value = "authorization") String authorization) {

    List<Object> resultList = null;
    if (isAuthorized(authorization)) {
        resultList = service.getRecords(firstName, lastName, city);
    }
    return ResponseEntity.ok().body(resultList);
}
0 Answers
Related