Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 112d104

Browse files
committed
C#: ZipSlip - remove ZipSlip prefix from TaintTracking class name.
1 parent b6c9f84 commit 112d104

2 files changed

Lines changed: 3 additions & 3 deletions

File tree

csharp/ql/src/Security Features/CWE-022/ZipSlip.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,6 @@
1212
import csharp
1313
import semmle.code.csharp.security.dataflow.ZipSlip::ZipSlip
1414

15-
from ZipSlipTaintTrackingConfiguration zipTaintTracking, DataFlow::Node source, DataFlow::Node sink
15+
from TaintTrackingConfiguration zipTaintTracking, DataFlow::Node source, DataFlow::Node sink
1616
where zipTaintTracking.hasFlow(source, sink)
1717
select sink, "Make sure to sanitize relative archive item path before creating path for file extraction if the source of $@ is untrusted", source, "zip archive"

csharp/ql/src/semmle/code/csharp/security/dataflow/ZipSlip.qll

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,8 +21,8 @@ module ZipSlip {
2121
abstract class Sanitizer extends DataFlow::ExprNode { }
2222

2323
/** A taint tracking configuration for ZipSlip */
24-
class ZipSlipTaintTrackingConfiguration extends TaintTracking::Configuration {
25-
ZipSlipTaintTrackingConfiguration() {
24+
class TaintTrackingConfiguration extends TaintTracking::Configuration {
25+
TaintTrackingConfiguration() {
2626
this = "ZipSlipTaintTracking"
2727
}
2828

0 commit comments

Comments
 (0)