Java/UnsafeDeserializationQuery

java/ql/src/Security/CWE/CWE-502/UnsafeDeserialization.ql
This commit is contained in:
Nora Dimitrijević
2025-10-09 14:38:37 +02:00
parent 4439322e88
commit 518c0818a4

View File

@@ -313,6 +313,8 @@ private module UnsafeDeserializationConfig implements DataFlow::ConfigSig {
predicate observeDiffInformedIncrementalMode() { any() }
Location getASelectedSinkLocation(DataFlow::Node sink) {
result = sink.getLocation()
or
result = sink.(UnsafeDeserializationSink).getMethodCall().getLocation()
}
}