No rule to check for missing global error handler on web pages

web
sonarweb

(Ankur) #1

SonarQube 6.7.4.

There is no rule available to detect missing global error handler on web pages (e.g. <%@page errorPage directive on jsp pages). This might mean that detailed error information may be unintentionally shown to the user, thus exposing critical information.

This is also documented in CWE-544.