diff --git a/java/ql/src/Security/CWE/CWE-023/PartialPathTraversal.ql b/java/ql/src/Security/CWE/CWE-023/PartialPathTraversal.ql index de426bf0d69..3b607d66593 100644 --- a/java/ql/src/Security/CWE/CWE-023/PartialPathTraversal.ql +++ b/java/ql/src/Security/CWE/CWE-023/PartialPathTraversal.ql @@ -4,7 +4,7 @@ * @kind problem * @problem.severity error * @security-severity 9.3 - * @precision high + * @precision medium * @id java/partial-path-traversal * @tags security * external/cwe/cwe-023 diff --git a/java/ql/src/Security/CWE/CWE-023/PartialPathTraversalFromRemote.qhelp b/java/ql/src/Security/CWE/CWE-023/PartialPathTraversalFromRemote.qhelp index ef9802ae45d..15b6f6eb962 100644 --- a/java/ql/src/Security/CWE/CWE-023/PartialPathTraversalFromRemote.qhelp +++ b/java/ql/src/Security/CWE/CWE-023/PartialPathTraversalFromRemote.qhelp @@ -4,6 +4,8 @@ +

See also java/partial-path-traversal, which is similar to this query, +but may also flag non-exploitable instances of Partial Path Traversal.