mirror of
https://github.com/github/codeql.git
synced 2025-12-24 04:36:35 +01:00
Add DefaultFullHttpResponse to Netty Check
This commit is contained in:
committed by
GitHub
parent
c77a921b06
commit
832a4f2e07
@@ -29,5 +29,12 @@ private class InsecureDefaultHttpResponseClassInstantiation extends InsecureNett
|
||||
}
|
||||
}
|
||||
|
||||
private class InsecureDefaultFullHttpResponseClassInstantiation extends InsecureNettyObjectCreation {
|
||||
InsecureDefaultHttpResponseClassInstantiation() {
|
||||
getConstructedType().hasQualifiedName("io.netty.handler.codec.http", "DefaultFullHttpResponse") and
|
||||
getArgument(3).(CompileTimeConstantExpr).getBooleanValue() = false
|
||||
}
|
||||
}
|
||||
|
||||
from InsecureNettyObjectCreation new
|
||||
select new, "Response-splitting vulnerability due to header value verification being disabled."
|
||||
|
||||
Reference in New Issue
Block a user