Update TimingAttackAgainstSensitiveInfo.ql

This commit is contained in:
Ahmed Farid
2022-07-26 15:37:02 +01:00
committed by GitHub
parent 961cc8778f
commit 912f40255d

View File

@@ -24,7 +24,7 @@ class ClientSuppliedSecretConfig extends TaintTracking::Configuration {
override predicate isSource(DataFlow::Node source) { source.asExpr() instanceof CredentialExpr }
override predicate isSink(DataFlow::Node sink) { sink instanceof CompareSink }
override predicate isSink(DataFlow::Node sink) { sink instanceof NonConstantTimeComparisonOfSecretSink }
}
from ClientSuppliedSecretConfig config, DataFlow::PathNode source, DataFlow::PathNode sink