mirror of
https://github.com/github/codeql.git
synced 2026-04-25 08:45:14 +02:00
Add XPath.evaluate as XXE sink
This commit is contained in:
4
java/ql/src/change-notes/2023-05-15-xpath-xxe-sink.md
Normal file
4
java/ql/src/change-notes/2023-05-15-xpath-xxe-sink.md
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
category: minorAnalysis
|
||||
---
|
||||
* The queries `java/xxe` and `java/xxe-local` now recognize the second argument of calls to `XPath.evaluate` as a sink.
|
||||
Reference in New Issue
Block a user