mirror of
https://github.com/github/codeql.git
synced 2026-05-01 03:35:13 +02:00
Update ZipSlip.qll
This commit is contained in:
@@ -9,8 +9,11 @@ class ZipSlipConfig extends TaintTracking::Configuration {
|
||||
override predicate isSource(DataFlow::Node source) {
|
||||
source = API::moduleImport("zipfile").getMember("ZipFile").getACall() or
|
||||
source = API::moduleImport("tarfile").getMember("open").getACall() or
|
||||
source = API::moduleImport("gzip").getMember("open").getACall() or
|
||||
source = API::moduleImport("bz2").getMember("open").getACall()
|
||||
source = API::moduleImport("tarfile").getMember("TarFile").getACall() or
|
||||
source = API::moduleImport("bz2").getMember("open").getACall() or
|
||||
source = API::moduleImport("bz2").getMember("BZ2File").getACall() or
|
||||
source = API::moduleImport("gzip").getMember("GzipFile").getACall() or
|
||||
source = API::moduleImport("gzip").getMember("open").getACall()
|
||||
}
|
||||
|
||||
override predicate isSink(DataFlow::Node sink) {
|
||||
|
||||
Reference in New Issue
Block a user