Files
codeql/java/change-notes/2021-05-28-remove-senderror-xss-sink.md
2021-05-28 15:13:19 +02:00

3 lines
295 B
Markdown

lgtm,codescanning
* The query "Cross-site scripting" (`java/xss`) has been improved to report fewer false positives by removing the `javax.servlet.http.HttpServletResponse.sendError` sink since Servlet API implementations generally already escape the error message, preventing script injection.