Java: Refactor RequestForgery.ql

This commit is contained in:
Anders Schack-Mulligen
2023-03-07 11:39:03 +01:00
parent 35beadc3bb
commit cc75a1a97e
2 changed files with 29 additions and 4 deletions

View File

@@ -13,9 +13,9 @@
import java
import semmle.code.java.security.RequestForgeryConfig
import DataFlow::PathGraph
import RequestForgeryFlow::PathGraph
from DataFlow::PathNode source, DataFlow::PathNode sink, RequestForgeryConfiguration conf
where conf.hasFlowPath(source, sink)
from RequestForgeryFlow::PathNode source, RequestForgeryFlow::PathNode sink
where RequestForgeryFlow::hasFlowPath(source, sink)
select sink.getNode(), source, sink, "Potential server-side request forgery due to a $@.",
source.getNode(), "user-provided value"