Fix bug in UnsafeFieldReadSanitizer

This commit is contained in:
Owen Mansel-Chan
2025-09-30 12:05:06 +01:00
parent b5fda88bd3
commit 5b07e8c9c4

View File

@@ -49,7 +49,7 @@ module SafeUrlFlow {
UnsafeFieldReadSanitizer() {
exists(DataFlow::FieldReadNode frn, string name |
name = ["Fragment", "RawQuery", "User"] and
frn.getField().hasQualifiedName("net/url", "URL")
frn.getField().hasQualifiedName("net/url", "URL", name)
|
this = frn.getBase()
)