From 72ef4983dbf475c0d395be40edc4080e36b3fb78 Mon Sep 17 00:00:00 2001 From: Timo Mueller Date: Fri, 25 Jun 2021 16:11:37 +0200 Subject: [PATCH] Fixed wrong match for symbolic constant --- .../CWE/CWE-665/InsecureRmiJmxEnvironmentConfiguration.ql | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/java/ql/src/experimental/Security/CWE/CWE-665/InsecureRmiJmxEnvironmentConfiguration.ql b/java/ql/src/experimental/Security/CWE/CWE-665/InsecureRmiJmxEnvironmentConfiguration.ql index eab6f1f7717..cf8e65c3bfb 100644 --- a/java/ql/src/experimental/Security/CWE/CWE-665/InsecureRmiJmxEnvironmentConfiguration.ql +++ b/java/ql/src/experimental/Security/CWE/CWE-665/InsecureRmiJmxEnvironmentConfiguration.ql @@ -59,7 +59,7 @@ class SafeFlow extends DataFlow::Configuration { .(FieldAccess) .getField() .hasQualifiedName("javax.management.remote.rmi", "RMIConnectorServer", - ["CREDENTIAL_TYPES", "CREDENTIALS_FILTER_PATTERN", "SERIAL_FILTER_PATTERN"]) + ["CREDENTIAL_TYPES", "CREDENTIALS_FILTER_PATTERN"]) | put.getQualifier() = qualifier and put.getMethod().(MapMethod).getReceiverKeyType() instanceof TypeString and