Files
codeql/java/change-notes/2021-08-03-spring-content-types.md
Chris Smowton 9d31641bb1 Add change note
2021-09-10 16:10:56 +01:00

297 B

lgtm,codescanning

  • The XSS query now accounts for more ways to set the content-type of an entity served via a Spring HTTP endpoint. This may flag more cases where an XSS-vulnerable content-type is set, and exclude more cases where a non-vulnerable content-type such as application/json is set.