From dd6257c7576b2dd4eead5fcbd799450bdaea1b2b Mon Sep 17 00:00:00 2001 From: Tony Torralba Date: Mon, 12 Sep 2022 11:58:56 +0200 Subject: [PATCH] Add security-severity --- java/ql/src/Security/CWE/CWE-094/TemplateInjection.ql | 1 + 1 file changed, 1 insertion(+) diff --git a/java/ql/src/Security/CWE/CWE-094/TemplateInjection.ql b/java/ql/src/Security/CWE/CWE-094/TemplateInjection.ql index da7a3908bfd..6ddd8cfd2c9 100644 --- a/java/ql/src/Security/CWE/CWE-094/TemplateInjection.ql +++ b/java/ql/src/Security/CWE/CWE-094/TemplateInjection.ql @@ -3,6 +3,7 @@ * @description Untrusted input interpreted as a template can lead to remote code execution. * @kind path-problem * @problem.severity error + * @security-severity 9.3 * @precision high * @id java/server-side-template-injection * @tags security