Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 832a4f2

Browse files
authored
Add DefaultFullHttpResponse to Netty Check
1 parent c77a921 commit 832a4f2

1 file changed

Lines changed: 7 additions & 0 deletions

File tree

java/ql/src/Security/CWE/CWE-113/NettyResponseSplitting.ql

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,5 +29,12 @@ private class InsecureDefaultHttpResponseClassInstantiation extends InsecureNett
2929
}
3030
}
3131

32+
private class InsecureDefaultFullHttpResponseClassInstantiation extends InsecureNettyObjectCreation {
33+
InsecureDefaultHttpResponseClassInstantiation() {
34+
getConstructedType().hasQualifiedName("io.netty.handler.codec.http", "DefaultFullHttpResponse") and
35+
getArgument(3).(CompileTimeConstantExpr).getBooleanValue() = false
36+
}
37+
}
38+
3239
from InsecureNettyObjectCreation new
3340
select new, "Response-splitting vulnerability due to header value verification being disabled."

0 commit comments

Comments
 (0)