mirror of
https://github.com/github/codeql.git
synced 2026-04-24 00:05:14 +02:00
Java: Whitelist Cookie::getName for HTTP response splitting.
This commit is contained in:
@@ -32,6 +32,7 @@ class HeaderSplittingSink extends DataFlow::ExprNode {
|
||||
|
||||
class WhitelistedSource extends RemoteUserInput {
|
||||
WhitelistedSource() {
|
||||
this.asExpr().(MethodAccess).getMethod() instanceof HttpServletRequestGetHeaderMethod
|
||||
this.asExpr().(MethodAccess).getMethod() instanceof HttpServletRequestGetHeaderMethod or
|
||||
this.asExpr().(MethodAccess).getMethod() instanceof CookieGetNameMethod
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user