Java/ConditionalBypass

java/ql/src/Security/CWE/CWE-807/ConditionalBypass.ql
This commit is contained in:
Nora Dimitrijević
2025-10-09 10:15:54 +02:00
parent 4482e831d7
commit dc1dff98b0

View File

@@ -51,6 +51,8 @@ module ConditionalBypassFlowConfig implements DataFlow::ConfigSig {
predicate observeDiffInformedIncrementalMode() { any() }
Location getASelectedSinkLocation(DataFlow::Node sink) {
result = sink.getLocation()
or
exists(MethodCall m, Expr e | result = [m, e].getLocation() |
conditionControlsMethod(m, e) and
sink.asExpr() = e