Java: Whitelist Cookie::getName for HTTP response splitting.

This commit is contained in:
Anders Schack-Mulligen
2018-10-25 12:02:33 +02:00
parent c78f3f8edf
commit 1188e18837

View File

@@ -32,6 +32,7 @@ class HeaderSplittingSink extends DataFlow::ExprNode {
class WhitelistedSource extends RemoteUserInput {
WhitelistedSource() {
this.asExpr().(MethodAccess).getMethod() instanceof HttpServletRequestGetHeaderMethod
this.asExpr().(MethodAccess).getMethod() instanceof HttpServletRequestGetHeaderMethod or
this.asExpr().(MethodAccess).getMethod() instanceof CookieGetNameMethod
}
}