Refactor JndiInjection

This commit is contained in:
Ed Minnix
2023-03-21 17:42:19 -04:00
parent 8bf3315bb5
commit 423ab1d9cf
3 changed files with 33 additions and 13 deletions

View File

@@ -13,9 +13,9 @@
import java
import semmle.code.java.security.JndiInjectionQuery
import DataFlow::PathGraph
import JndiInjectionFlow::PathGraph
from DataFlow::PathNode source, DataFlow::PathNode sink, JndiInjectionFlowConfig conf
where conf.hasFlowPath(source, sink)
from JndiInjectionFlow::PathNode source, JndiInjectionFlow::PathNode sink
where JndiInjectionFlow::hasFlowPath(source, sink)
select sink.getNode(), source, sink, "JNDI lookup might include name from $@.", source.getNode(),
"this user input"