From 9d3e8ec4757e7264ebcdd0c36bb74399fa25c81a Mon Sep 17 00:00:00 2001 From: Shyam Mehta Date: Mon, 8 Aug 2022 17:34:06 -0400 Subject: [PATCH] Update PartialPathTraversalFromRemote.qhelp --- java/ql/src/Security/CWE/CWE-023/PartialPathTraversal.ql | 2 +- .../Security/CWE/CWE-023/PartialPathTraversalFromRemote.qhelp | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/java/ql/src/Security/CWE/CWE-023/PartialPathTraversal.ql b/java/ql/src/Security/CWE/CWE-023/PartialPathTraversal.ql index de426bf0d69..3b607d66593 100644 --- a/java/ql/src/Security/CWE/CWE-023/PartialPathTraversal.ql +++ b/java/ql/src/Security/CWE/CWE-023/PartialPathTraversal.ql @@ -4,7 +4,7 @@ * @kind problem * @problem.severity error * @security-severity 9.3 - * @precision high + * @precision medium * @id java/partial-path-traversal * @tags security * external/cwe/cwe-023 diff --git a/java/ql/src/Security/CWE/CWE-023/PartialPathTraversalFromRemote.qhelp b/java/ql/src/Security/CWE/CWE-023/PartialPathTraversalFromRemote.qhelp index ef9802ae45d..15b6f6eb962 100644 --- a/java/ql/src/Security/CWE/CWE-023/PartialPathTraversalFromRemote.qhelp +++ b/java/ql/src/Security/CWE/CWE-023/PartialPathTraversalFromRemote.qhelp @@ -4,6 +4,8 @@ +

See also java/partial-path-traversal, which is similar to this query, +but may also flag non-exploitable instances of Partial Path Traversal.