diff --git a/java/ql/src/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll b/java/ql/src/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll index a1d5d830665..65c0dc1d4be 100644 --- a/java/ql/src/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll +++ b/java/ql/src/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll @@ -389,6 +389,10 @@ private predicate taintPreservingQualifierToMethod(Method m) { ) or m instanceof StringReplaceMethod + or + exists(SpringUntrustedDataType dt | + m.(GetterMethod) = dt.getAMethod() + ) } private class StringReplaceMethod extends Method {