JS: Fix observed FPs in UnsafeJQueryPlugin

This commit is contained in:
Asger F
2023-04-13 15:52:38 +02:00
parent b321151a28
commit 0d598c437d

View File

@@ -23,6 +23,9 @@ class Configuration extends TaintTracking::Configuration {
node instanceof DomBasedXss::Sanitizer
or
node instanceof Sanitizer
or
// Plugins usually do `$(this)` to coerce an existing DOM element to a jQuery object.
node instanceof DataFlow::ThisNode
}
override predicate isAdditionalTaintStep(DataFlow::Node src, DataFlow::Node sink) {