Update java/ql/src/Security/CWE/CWE-113/NettyResponseSplitting.ql

This commit is contained in:
Jonathan Leitschuh
2020-02-05 12:45:47 -05:00
committed by GitHub
parent 832a4f2e07
commit 60f2fa9eb9

View File

@@ -30,7 +30,7 @@ private class InsecureDefaultHttpResponseClassInstantiation extends InsecureNett
}
private class InsecureDefaultFullHttpResponseClassInstantiation extends InsecureNettyObjectCreation {
InsecureDefaultHttpResponseClassInstantiation() {
InsecureDefaultFullHttpResponseClassInstantiation() {
getConstructedType().hasQualifiedName("io.netty.handler.codec.http", "DefaultFullHttpResponse") and
getArgument(3).(CompileTimeConstantExpr).getBooleanValue() = false
}