Python: make sure code injection query is using correct sources.

This commit is contained in:
Mark Shannon
2019-03-06 17:32:43 +00:00
parent 35e82dca68
commit bc19769e6d

View File

@@ -27,7 +27,7 @@ class CodeInjectionConfiguration extends TaintTracking::Configuration {
CodeInjectionConfiguration() { this = "Code injection configuration" }
override predicate isSource(TaintTracking::Source source) { source.isSourceOf(any(UntrustedStringKind u)) }
override predicate isSource(TaintTracking::Source source) { source instanceof HttpRequestTaintSource }
override predicate isSink(TaintTracking::Sink sink) { sink instanceof StringEvaluationNode }