Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 475cca0

Browse files
Update ZipSlip.qll
1 parent 27b9d6c commit 475cca0

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

  • python/ql/src/experimental/semmle/python/security

python/ql/src/experimental/semmle/python/security/ZipSlip.qll

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,9 @@ class ZipSlipConfig extends TaintTracking::Configuration {
1313
source = API::moduleImport("bz2").getMember("open").getACall() or
1414
source = API::moduleImport("bz2").getMember("BZ2File").getACall() or
1515
source = API::moduleImport("gzip").getMember("GzipFile").getACall() or
16-
source = API::moduleImport("gzip").getMember("open").getACall()
16+
source = API::moduleImport("gzip").getMember("open").getACall() or
17+
source = API::moduleImport("lzma").getMember("open").getACall() or
18+
source = API::moduleImport("lzma").getMember("LZMAFile").getACall()
1719
}
1820

1921
override predicate isSink(DataFlow::Node sink) {

0 commit comments

Comments
 (0)