问题 I am using Fortify SCA to find the security issues in my application (as a university homework). I have encountered some 'Log Forging' issues which I am not able to get rid off. Basically, I log some values that come as user input from a web interface: logger.warn("current id not valid - " + bean.getRecordId())); and Fortify reports this as a log forging issue, because the getRecordId() returns an user input. I have followed this article, and I am replacing the 'new line' with space, but the