Add XPath.evaluate as XXE sink

This commit is contained in:
Tony Torralba
2023-05-15 17:39:35 +02:00
parent 9dede31c0d
commit 7d79d87d48
4 changed files with 59 additions and 19 deletions

View File

@@ -0,0 +1,4 @@
---
category: minorAnalysis
---
* The queries `java/xxe` and `java/xxe-local` now recognize the second argument of calls to `XPath.evaluate` as a sink.