mirror of
https://github.com/github/codeql.git
synced 2025-12-18 09:43:15 +01:00
Will need subsequent PRs fixing up test failures (due to deprecated methods moving around), but other than that everything should be straight-forward.
13 lines
465 B
Plaintext
13 lines
465 B
Plaintext
import python
|
|
import semmle.python.security.Exceptions
|
|
import semmle.python.web.HttpResponse
|
|
|
|
from TaintedNode n, TaintedNode s
|
|
where
|
|
s = n.getASuccessor() and
|
|
not n.getLocation().getFile().inStdlib() and
|
|
not s.getLocation().getFile().inStdlib()
|
|
select "Taint " + n.getTaintKind(), n.getLocation().toString(), n.getNode().toString(),
|
|
n.getContext(), " --> ", "Taint " + s.getTaintKind(), s.getLocation().toString(),
|
|
s.getNode().toString(), s.getContext()
|