Sonarqube showing critical vulnerability on PersistenceContext EntityManager

Viewed 421

On scanning my Spring Boot project using Sonarqube, I got the issue on:

@PersistenceContext
private EntityManager em;

The issue says:

Spring @Component, @Controller, @Service, and @Repository classes are singletons by default, meaning only one instance of the class is ever instantiated in the application. Typically such a class might have a few static members, such as a logger, but all non-static members should be managed by Spring. That is, they should have one of these annotations: @Resource, @Inject, @Autowired or @Value.

Having non-injected members in one of these classes could indicate an attempt to manage state. Because they are singletons, such an attempt is almost guaranteed to eventually expose data from User1's session to User2.

This rule raises an issue when a singleton @Controller, @Service, or @Repository has non-static members that are not annotated with one of:

org.springframework.beans.factory.annotation.Autowired

org.springframework.beans.factory.annotation.Value

javax.annotation.Inject

javax.annotation.Resource

So, is this actually an issue? or just a False Positives? Is it good idea to move all these queries to JpaRepository?

0 Answers
Related