Merge pull request #520 from esben-semmle/js/clear-text-logging-taint-kinds

Approved by asger-semmle
This commit is contained in:
semmle-qlci
2018-11-23 12:40:40 +00:00
committed by GitHub
4 changed files with 35 additions and 8 deletions

View File

@@ -52,7 +52,7 @@ module CleartextLogging {
}
override predicate isAdditionalFlowStep(DataFlow::Node src, DataFlow::Node trg) {
any (TaintTracking::StringConcatenationTaintStep s).step(src, trg)
StringConcatenation::taintStep(src, trg)
or
exists (string name | name = "toString" or name = "valueOf" |
src.(DataFlow::SourceNode).getAMethodCall(name) = trg