mirror of
https://github.com/github/codeql.git
synced 2025-12-24 04:36:35 +01:00
Generalize QueryInjectionSink
Extends from the more general DataFlow::Node instead of DataFlow::ExprNode
This commit is contained in:
@@ -40,7 +40,7 @@ class UncontrolledStringBuilderSourceFlowConfig extends TaintTracking::Configura
|
||||
from QueryInjectionSink query, Expr uncontrolled
|
||||
where
|
||||
(
|
||||
builtFromUncontrolledConcat(query.getExpr(), uncontrolled)
|
||||
builtFromUncontrolledConcat(query.asExpr(), uncontrolled)
|
||||
or
|
||||
exists(StringBuilderVar sbv, UncontrolledStringBuilderSourceFlowConfig conf |
|
||||
uncontrolledStringBuilderQuery(sbv, uncontrolled) and
|
||||
|
||||
Reference in New Issue
Block a user