Files
codeql/javascript/ql/test/query-tests/Security/CWE-834/LoopBoundInjectionLodash.js
2019-09-13 11:12:01 +01:00

15 lines
274 B
JavaScript

'use strict';
var _ = require('lodash');
var express = require('express');
var router = new express.Router();
var rootRoute = router.route('foobar');
rootRoute.post(function(req, res) {
problem(req.body);
});
function problem(val) {
_.chunk(val, 2); // NOT OK!
}