Merge pull request #8702 from jketema/command-line-sanitizer

C++: Use `isSanitizerOut(DataFlow::Node node)` in `cpp/command-line-injection`
This commit is contained in:
Jeroen Ketema
2022-04-08 23:42:35 +02:00
committed by GitHub

View File

@@ -116,8 +116,8 @@ class ExecTaintConfiguration extends TaintTracking::Configuration {
state instanceof ConcatState
}
override predicate isSanitizerOut(DataFlow::Node node, DataFlow::FlowState state) {
isSink(node, state) // Prevent duplicates along a call chain, since `shellCommand` will include wrappers
override predicate isSanitizerOut(DataFlow::Node node) {
isSink(node, _) // Prevent duplicates along a call chain, since `shellCommand` will include wrappers
}
}