mirror of
https://github.com/github/codeql.git
synced 2025-12-17 09:13:20 +01:00
Python: make sure code injection query is using correct sources.
This commit is contained in:
@@ -27,7 +27,7 @@ class CodeInjectionConfiguration extends TaintTracking::Configuration {
|
||||
|
||||
CodeInjectionConfiguration() { this = "Code injection configuration" }
|
||||
|
||||
override predicate isSource(TaintTracking::Source source) { source.isSourceOf(any(UntrustedStringKind u)) }
|
||||
override predicate isSource(TaintTracking::Source source) { source instanceof HttpRequestTaintSource }
|
||||
|
||||
override predicate isSink(TaintTracking::Sink sink) { sink instanceof StringEvaluationNode }
|
||||
|
||||
|
||||
Reference in New Issue
Block a user