diff --git a/java/ql/src/Security/CWE/CWE-347/MissingJWTSignatureCheck.ql b/java/ql/src/Security/CWE/CWE-347/MissingJWTSignatureCheck.ql index b17915a8fd5..30caee117c8 100644 --- a/java/ql/src/Security/CWE/CWE-347/MissingJWTSignatureCheck.ql +++ b/java/ql/src/Security/CWE/CWE-347/MissingJWTSignatureCheck.ql @@ -1,6 +1,6 @@ /** * @name Missing JWT signature check - * @description Failing to check the JWT signature may allow an attacker to forge their own tokens. + * @description Failing to check the Json Web Token (JWT) signature may allow an attacker to forge their own tokens. * @kind path-problem * @problem.severity error * @security-severity 7.8 diff --git a/java/ql/src/semmle/code/java/dataflow/ExternalFlow.qll b/java/ql/src/semmle/code/java/dataflow/ExternalFlow.qll index fa1461768c3..e3d9e7e35cf 100644 --- a/java/ql/src/semmle/code/java/dataflow/ExternalFlow.qll +++ b/java/ql/src/semmle/code/java/dataflow/ExternalFlow.qll @@ -97,7 +97,6 @@ private module Frameworks { private import semmle.code.java.security.ResponseSplitting private import semmle.code.java.security.InformationLeak private import semmle.code.java.security.JexlInjectionSinkModels - private import semmle.code.java.security.JWT private import semmle.code.java.security.LdapInjection private import semmle.code.java.security.XPath private import semmle.code.java.frameworks.android.SQLite diff --git a/java/ql/src/semmle/code/java/security/JWT.qll b/java/ql/src/semmle/code/java/security/JWT.qll index d7fec0ea958..3f4453c62dd 100644 --- a/java/ql/src/semmle/code/java/security/JWT.qll +++ b/java/ql/src/semmle/code/java/security/JWT.qll @@ -1,4 +1,4 @@ -/** Provides classes for working with JWT libraries. */ +/** Provides classes for working with JSON Web Token (JWT) libraries. */ import java private import semmle.code.java.dataflow.ExternalFlow diff --git a/java/ql/src/semmle/code/java/security/MissingJWTSignatureCheckQuery.qll b/java/ql/src/semmle/code/java/security/MissingJWTSignatureCheckQuery.qll index f70b9ab6447..82c03640875 100644 --- a/java/ql/src/semmle/code/java/security/MissingJWTSignatureCheckQuery.qll +++ b/java/ql/src/semmle/code/java/security/MissingJWTSignatureCheckQuery.qll @@ -1,8 +1,7 @@ -/** Provides classes to be used in queries related to JWT signature vulnerabilities. */ +/** Provides classes to be used in queries related to JSON Web Token (JWT) signature vulnerabilities. */ import java import semmle.code.java.dataflow.DataFlow -import semmle.code.java.dataflow.ExternalFlow import semmle.code.java.security.JWT /**