Removed LocalUserInput in JexlInjectionLib.ql

This commit is contained in:
Artem Smotrakov
2021-01-29 12:38:51 +01:00
parent 8d701e604a
commit 59f48ecea3

View File

@@ -12,8 +12,7 @@ class JexlInjectionConfig extends TaintTracking::Configuration {
override predicate isSource(DataFlow::Node source) {
source instanceof TaintedSpringRequestBody or
source instanceof RemoteFlowSource or
source instanceof LocalUserInput
source instanceof RemoteFlowSource
}
override predicate isSink(DataFlow::Node sink) { sink instanceof JexlEvaluationSink }