Create 2022-08-03-tainted-path-mad.md

This commit is contained in:
Chris Smowton
2022-08-03 10:54:35 +01:00
committed by GitHub
parent 84a4b6a866
commit 977823bd76

View File

@@ -0,0 +1,4 @@
---
category: minorAnalysis
---
* The query `java/path-injection` now recognises vulnerable APIs defined using the `SinkModelCsv` class with the `create-file` type. Out of the box this includes Apache Commons-IO functions, as well as any user-defined sinks.