Merge pull request #11282 from egregius313/egregiu313/webview-addjavascriptinterface

Java: Query for detecting addJavascriptInterface method calls
This commit is contained in:
Edward Minnix III
2022-12-19 11:28:45 -05:00
committed by GitHub
8 changed files with 108 additions and 0 deletions

View File

@@ -0,0 +1 @@
| WebViewAddJavascriptInterface.java:10:9:10:61 | addJavascriptInterface(...) | JavaScript interface to Java object added in Android WebView. |

View File

@@ -0,0 +1,12 @@
package com.example.test;
import android.webkit.WebView;
class WebViewAddJavascriptInterface {
class Greeter {
}
public void addGreeter(WebView view) {
view.addJavascriptInterface(new Greeter(), "greeter");
}
}

View File

@@ -0,0 +1 @@
Security/CWE/CWE-079/AndroidWebViewAddJavascriptInterface.ql