Update java/ql/src/semmle/code/java/frameworks/jackson/JacksonSerializability.qll

Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
This commit is contained in:
Jonathan Leitschuh
2021-05-12 08:58:01 -04:00
committed by GitHub
parent 5a68ac88ef
commit 48b50f93c2

View File

@@ -53,7 +53,10 @@ private class JacksonWriteValueMethod extends Method, TaintPreservingCallable {
private class JacksonReadValueMethod extends Method, TaintPreservingCallable {
JacksonReadValueMethod() {
getDeclaringType().hasQualifiedName("com.fasterxml.jackson.databind", "ObjectReader") and
(
getDeclaringType().hasQualifiedName("com.fasterxml.jackson.databind", "ObjectReader") or
getDeclaringType().hasQualifiedName("com.fasterxml.jackson.databind", "ObjectMapper")
) and
hasName(["readValue", "readValues"])
}