Description
CWE: 256 Plaintext Storage of a Password. Read the password from a Properties file or a regular file. In the good case, read the file from the console.
BadSource: Read password from a .properties file (from the property named password)
GoodSource: Read password from a .properties file (from the property named password) and then decrypt it
Sinks:
GoodSink: Decrypt password and use decrypted password as password to connect to DB
BadSink : Use password as password to connect to DB
Flow Variant: 09 Control flow: if(IO.STATIC_FINAL_TRUE) and if(IO.STATIC_FINAL_FALSE)
Flaws
Test Suites
Documentation
Have any comments on this test case? Please, send us an email.