File tree Expand file tree Collapse file tree
semmle/code/java/dataflow Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -50,7 +50,7 @@ class TrustAllHostnameVerifierConfiguration extends DataFlow::Configuration {
5050 source .asExpr ( ) .( ClassInstanceExpr ) .getConstructedType ( ) instanceof TrustAllHostnameVerifier
5151 }
5252
53- override predicate isSink ( DataFlow:: Node sink ) { sinkNode ( sink , "set-hostname" ) }
53+ override predicate isSink ( DataFlow:: Node sink ) { sinkNode ( sink , "set-hostname-verifier " ) }
5454
5555 override predicate isBarrier ( DataFlow:: Node barrier ) {
5656 // ignore nodes that are in functions that intentionally disable hostname verification
Original file line number Diff line number Diff line change @@ -209,8 +209,8 @@ private predicate sinkModelCsv(string row) {
209209 // Bean validation
210210 "javax.validation;ConstraintValidatorContext;true;buildConstraintViolationWithTemplate;;;Argument[0];bean-validation" ,
211211 // Set hostname
212- "javax.net.ssl;HttpsURLConnection;true;setDefaultHostnameVerifier;;;Argument[0];set-hostname" ,
213- "javax.net.ssl;HttpsURLConnection;true;setHostnameVerifier;;;Argument[0];set-hostname"
212+ "javax.net.ssl;HttpsURLConnection;true;setDefaultHostnameVerifier;;;Argument[0];set-hostname-verifier " ,
213+ "javax.net.ssl;HttpsURLConnection;true;setHostnameVerifier;;;Argument[0];set-hostname-verifier "
214214 ]
215215}
216216
You can’t perform that action at this time.
0 commit comments