title | description | ms.date | author | ms.author | dev_langs | f1_keywords | |||
---|---|---|---|---|---|---|---|---|---|
CA3007: Review code for open redirect vulnerabilities (code analysis) |
Learn about code analysis rule CA3007: Review code for open redirect vulnerabilities |
04/03/2019 |
dotpaul |
paulming |
|
|
Property | Value |
---|---|
Rule ID | CA3007 |
Title | Review code for open redirect vulnerabilities |
Category | Security |
Fix is breaking or non-breaking | Non-breaking |
Enabled by default in .NET 8 | No |
Potentially untrusted HTTP request input reaches an HTTP response redirect.
By default, this rule analyzes the entire codebase, but this is configurable.
When working with untrusted input, be mindful of open redirect vulnerabilities. An attacker can exploit an open redirect vulnerability to use your website to give the appearance of a legitimate URL, but redirect an unsuspecting visitor to a phishing or other malicious webpage.
This rule attempts to find input from HTTP requests reaching an HTTP redirect URL.
Note
This rule can't track data across assemblies. For example, if one assembly reads the HTTP request input and then passes it to another assembly that responds with an HTTP redirect, this rule won't produce a warning.
Note
There is a configurable limit to how deep this rule will analyze data flow across method calls. See Analyzer Configuration for how to configure the limit in an EditorConfig file.
Some approaches to fixing open redirect vulnerabilities include:
- Don't allow users to initiate redirects.
- Don't allow users to specify any part of the URL in a redirect scenario.
- Restrict redirects to a predefined "allow list" of URLs.
- Validate redirect URLs.
- If applicable, consider using a disclaimer page when users are being redirected away from your site.
If you know you've validated the input to be restricted to intended URLs, it's okay to suppress this warning.
If you just want to suppress a single violation, add preprocessor directives to your source file to disable and then re-enable the rule.
#pragma warning disable CA3007
// The code that's violating the rule is on this line.
#pragma warning restore CA3007
To disable the rule for a file, folder, or project, set its severity to none
in the configuration file.
[*.{cs,vb}]
dotnet_diagnostic.CA3007.severity = none
For more information, see How to suppress code analysis warnings.
Use the following options to configure which parts of your codebase to run this rule on.
You can configure these options for just this rule, for all rules it applies to, or for all rules in this category (Security) that it applies to. For more information, see Code quality rule configuration options.
[!INCLUDEexcluded-symbol-names]
[!INCLUDEexcluded-type-names-with-derived-types]
using System;
public partial class WebForm : System.Web.UI.Page
{
protected void Page_Load(object sender, EventArgs e)
{
string input = Request.Form["url"];
this.Response.Redirect(input);
}
}
Imports System
Partial Public Class WebForm
Inherits System.Web.UI.Page
Protected Sub Page_Load(sender As Object, eventArgs As EventArgs)
Dim input As String = Me.Request.Form("url")
Me.Response.Redirect(input)
End Sub
End Class
using System;
public partial class WebForm : System.Web.UI.Page
{
protected void Page_Load(object sender, EventArgs e)
{
string input = Request.Form["in"];
if (String.IsNullOrWhiteSpace(input))
{
this.Response.Redirect("https://example.org/login.html");
}
}
}
Imports System
Partial Public Class WebForm
Inherits System.Web.UI.Page
Protected Sub Page_Load(sender As Object, eventArgs As EventArgs)
Dim input As String = Me.Request.Form("in")
If String.IsNullOrWhiteSpace(input) Then
Me.Response.Redirect("https://example.org/login.html")
End If
End Sub
End Class