Files
codeql/java/ql/test/query-tests/security/CWE-089/semmle/examples/getAnAppend.ql
2018-08-30 10:48:05 +01:00

13 lines
406 B
Plaintext

import semmle.code.java.dataflow.TaintTracking
from StringBuilderVar sbv, MethodAccess append, Method method
where sbv.getAnAppend() = append and append.getEnclosingCallable() = method
select
method.getName(),
sbv.getLocation().getStartLine() - method.getLocation().getStartLine(),
sbv,
append.getLocation().getStartLine() - method.getLocation().getStartLine(),
append,
append.getArgument(0)