Merge branch 'new_deser_sink' of https://github.com/pwntester/ql into new_deser_sink

This commit is contained in:
Alvaro Muñoz
2020-11-04 10:51:07 +01:00

View File

@@ -71,7 +71,7 @@ private class SnakeYamlParse extends MethodAccess {
SnakeYamlParse() {
exists(Method m |
m.getDeclaringType() instanceof Yaml and
(m.hasName("compose") or m.hasName("composeAll") or m.hasName("load") or m.hasName("loadAll") or m.hasName("loadAs") or m.hasName("parse")) and
m.hasName(["compose", "composeAll", "load", "loadAll", "loadAs", "parse"]) and
m = this.getMethod()
)
}