mirror of
https://github.com/github/codeql.git
synced 2026-04-27 01:35:13 +02:00
Create 2022-08-03-tainted-path-mad.md
This commit is contained in:
4
java/ql/src/change-notes/2022-08-03-tainted-path-mad.md
Normal file
4
java/ql/src/change-notes/2022-08-03-tainted-path-mad.md
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
category: minorAnalysis
|
||||
---
|
||||
* The query `java/path-injection` now recognises vulnerable APIs defined using the `SinkModelCsv` class with the `create-file` type. Out of the box this includes Apache Commons-IO functions, as well as any user-defined sinks.
|
||||
Reference in New Issue
Block a user