Update java/ql/src/Security/CWE/CWE-295/AndroidMissingCertificatePinning.ql

This commit is contained in:
Tony Torralba
2022-12-19 12:10:32 +01:00
committed by GitHub
parent a880fecc8b
commit 484a16ce1b

View File

@@ -3,7 +3,7 @@
* @description Network connections that do not use certificate pinning may allow attackers to eavesdrop communications. * @description Network connections that do not use certificate pinning may allow attackers to eavesdrop communications.
* @kind problem * @kind problem
* @problem.severity warning * @problem.severity warning
* @security-severity 7.5 * @security-severity 5.9
* @precision medium * @precision medium
* @id java/android/missing-certificate-pinning * @id java/android/missing-certificate-pinning
* @tags security * @tags security