Java


JAVA.INSEC.CERT.RS : Certificate Added to Root Store (Java)

Summary

Detected possible certificate added to root storage.

Having a hardcoded IP address is considered a bad practice. It can lead to several problems:

Some security protocols are now considered deprecated and unsafe and so, they must not be used.

Properties

Class Name Certificate Added to Root Store (Java)
Significance security
Mnemonic JAVA.INSEC.CERT.RS
Categories
CWE CWE:922 Insecure Storage of Sensitive Information
OWASP-2017 OWASP-2017:A2 Broken authentication
OWASP-2021 OWASP-2021:A7 Identification and authorization failures
Availability Available for Java only.
Enabling Checks for this warning class are disabled by default. To enable them, add the following WARNING_FILTER rule to the project configuration file.
WARNING_FILTER += allow class="Certificate Added to Root Store (Java)"

Resolution

Parameterize it in a configuration file.

Use safer protocols.

Relevant Configuration File Parameters

The following configuration file parameters affect checks for this warning class.