Merge pull request #6393 from luchua-bc/java/xss-jsf

Java: CWE-079 Query to detect XSS with JavaServer Faces (JSF)
This commit is contained in:
Chris Smowton
2021-09-14 15:15:56 +01:00
committed by GitHub
15 changed files with 2203 additions and 10 deletions

View File

@@ -36,7 +36,9 @@ class ServletWriterSourceToPrintStackTraceMethodFlowConfig extends TaintTracking
this = "StackTraceExposure::ServletWriterSourceToPrintStackTraceMethodFlowConfig"
}
override predicate isSource(DataFlow::Node src) { src.asExpr() instanceof ServletWriterSource }
override predicate isSource(DataFlow::Node src) {
src.asExpr() instanceof XssVulnerableWriterSource
}
override predicate isSink(DataFlow::Node sink) {
exists(MethodAccess ma |