Update ZipSlip.qll

This commit is contained in:
Ahmed Farid
2022-03-07 10:09:53 +01:00
committed by GitHub
parent 35a1c80ceb
commit 6685c6b4b3

View File

@@ -7,7 +7,10 @@ class ZipSlipConfig extends TaintTracking::Configuration {
ZipSlipConfig() { this = "ZipSlipConfig" }
override predicate isSource(DataFlow::Node source) {
source = API::moduleImport("zipfile").getMember("ZipFile").getACall()
source = API::moduleImport("zipfile").getMember("ZipFile").getACall() or
source = API::moduleImport("tarfile").getMember("open").getACall() or
source = API::moduleImport("gzip").getMember("open").getACall() or
source = API::moduleImport("bz2").getMember("open").getACall()
}
override predicate isSink(DataFlow::Node sink) {