Java/TaintedPermissionsCheckQuery

java/ql/src/Security/CWE/CWE-807/TaintedPermissionsCheck.ql
This commit is contained in:
Nora Dimitrijević
2025-10-09 14:14:10 +02:00
parent 697f428eae
commit 2a889f4f98

View File

@@ -63,8 +63,9 @@ module TaintedPermissionsCheckFlowConfig implements DataFlow::ConfigSig {
predicate observeDiffInformedIncrementalMode() { any() }
Location getASelectedSinkLocation(DataFlow::Node sink) {
exists(PermissionsConstruction p |
sink.asExpr() = p.getInput() and
exists(PermissionsConstruction p | sink.asExpr() = p.getInput() |
result = sink.getLocation()
or
result = p.getLocation()
)
}