@@ -36,11 +36,19 @@ edges
3636| VelocitySSTI.java:59:17:59:44 | getParameter(...) : String | VelocitySSTI.java:62:42:62:45 | code : String |
3737| VelocitySSTI.java:62:25:62:46 | new StringReader(...) : StringReader | VelocitySSTI.java:63:25:63:30 | reader |
3838| VelocitySSTI.java:62:42:62:45 | code : String | VelocitySSTI.java:62:25:62:46 | new StringReader(...) : StringReader |
39- | VelocitySSTI.java:69:17:69:44 | getParameter(...) : String | VelocitySSTI.java:77:21:77:27 | context |
40- | VelocitySSTI.java:83:17:83:44 | getParameter(...) : String | VelocitySSTI.java:89:60:89:66 | context |
41- | VelocitySSTI.java:95:17:95:44 | getParameter(...) : String | VelocitySSTI.java:102:11:102:17 | context |
42- | VelocitySSTI.java:108:17:108:44 | getParameter(...) : String | VelocitySSTI.java:115:11:115:17 | context |
43- | VelocitySSTI.java:120:17:120:44 | getParameter(...) : String | VelocitySSTI.java:123:37:123:40 | code |
39+ | VelocitySSTI.java:69:17:69:44 | getParameter(...) : String | VelocitySSTI.java:72:23:72:26 | code : String |
40+ | VelocitySSTI.java:72:3:72:9 | context [post update] : AbstractContext | VelocitySSTI.java:77:21:77:27 | context |
41+ | VelocitySSTI.java:72:23:72:26 | code : String | VelocitySSTI.java:72:3:72:9 | context [post update] : AbstractContext |
42+ | VelocitySSTI.java:83:17:83:44 | getParameter(...) : String | VelocitySSTI.java:86:23:86:26 | code : String |
43+ | VelocitySSTI.java:86:3:86:9 | context [post update] : AbstractContext | VelocitySSTI.java:90:52:90:58 | context |
44+ | VelocitySSTI.java:86:23:86:26 | code : String | VelocitySSTI.java:86:3:86:9 | context [post update] : AbstractContext |
45+ | VelocitySSTI.java:96:17:96:44 | getParameter(...) : String | VelocitySSTI.java:99:23:99:26 | code : String |
46+ | VelocitySSTI.java:99:3:99:9 | context [post update] : AbstractContext | VelocitySSTI.java:103:11:103:17 | context |
47+ | VelocitySSTI.java:99:23:99:26 | code : String | VelocitySSTI.java:99:3:99:9 | context [post update] : AbstractContext |
48+ | VelocitySSTI.java:109:17:109:44 | getParameter(...) : String | VelocitySSTI.java:112:23:112:26 | code : String |
49+ | VelocitySSTI.java:112:3:112:9 | context [post update] : AbstractContext | VelocitySSTI.java:116:11:116:17 | context |
50+ | VelocitySSTI.java:112:23:112:26 | code : String | VelocitySSTI.java:112:3:112:9 | context [post update] : AbstractContext |
51+ | VelocitySSTI.java:121:17:121:44 | getParameter(...) : String | VelocitySSTI.java:124:37:124:40 | code |
4452nodes
4553| FreemarkerSSTI.java:23:17:23:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
4654| FreemarkerSSTI.java:24:19:24:40 | new StringReader(...) : StringReader | semmle.label | new StringReader(...) : StringReader |
@@ -99,15 +107,23 @@ nodes
99107| VelocitySSTI.java:62:42:62:45 | code : String | semmle.label | code : String |
100108| VelocitySSTI.java:63:25:63:30 | reader | semmle.label | reader |
101109| VelocitySSTI.java:69:17:69:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
110+ | VelocitySSTI.java:72:3:72:9 | context [post update] : AbstractContext | semmle.label | context [post update] : AbstractContext |
111+ | VelocitySSTI.java:72:23:72:26 | code : String | semmle.label | code : String |
102112| VelocitySSTI.java:77:21:77:27 | context | semmle.label | context |
103113| VelocitySSTI.java:83:17:83:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
104- | VelocitySSTI.java:89:60:89:66 | context | semmle.label | context |
105- | VelocitySSTI.java:95:17:95:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
106- | VelocitySSTI.java:102:11:102:17 | context | semmle.label | context |
107- | VelocitySSTI.java:108:17:108:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
108- | VelocitySSTI.java:115:11:115:17 | context | semmle.label | context |
109- | VelocitySSTI.java:120:17:120:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
110- | VelocitySSTI.java:123:37:123:40 | code | semmle.label | code |
114+ | VelocitySSTI.java:86:3:86:9 | context [post update] : AbstractContext | semmle.label | context [post update] : AbstractContext |
115+ | VelocitySSTI.java:86:23:86:26 | code : String | semmle.label | code : String |
116+ | VelocitySSTI.java:90:52:90:58 | context | semmle.label | context |
117+ | VelocitySSTI.java:96:17:96:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
118+ | VelocitySSTI.java:99:3:99:9 | context [post update] : AbstractContext | semmle.label | context [post update] : AbstractContext |
119+ | VelocitySSTI.java:99:23:99:26 | code : String | semmle.label | code : String |
120+ | VelocitySSTI.java:103:11:103:17 | context | semmle.label | context |
121+ | VelocitySSTI.java:109:17:109:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
122+ | VelocitySSTI.java:112:3:112:9 | context [post update] : AbstractContext | semmle.label | context [post update] : AbstractContext |
123+ | VelocitySSTI.java:112:23:112:26 | code : String | semmle.label | code : String |
124+ | VelocitySSTI.java:116:11:116:17 | context | semmle.label | context |
125+ | VelocitySSTI.java:121:17:121:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
126+ | VelocitySSTI.java:124:37:124:40 | code | semmle.label | code |
111127subpaths
112128#select
113129| FreemarkerSSTI.java:27:35:27:40 | reader | FreemarkerSSTI.java:23:17:23:44 | getParameter(...) : String | FreemarkerSSTI.java:27:35:27:40 | reader | Potential arbitrary code execution due to $@. | FreemarkerSSTI.java:23:17:23:44 | getParameter(...) | a template value loaded from a remote source. |
@@ -130,7 +146,7 @@ subpaths
130146| VelocitySSTI.java:53:45:53:50 | reader | VelocitySSTI.java:44:17:44:44 | getParameter(...) : String | VelocitySSTI.java:53:45:53:50 | reader | Potential arbitrary code execution due to $@. | VelocitySSTI.java:44:17:44:44 | getParameter(...) | a template value loaded from a remote source. |
131147| VelocitySSTI.java:63:25:63:30 | reader | VelocitySSTI.java:59:17:59:44 | getParameter(...) : String | VelocitySSTI.java:63:25:63:30 | reader | Potential arbitrary code execution due to $@. | VelocitySSTI.java:59:17:59:44 | getParameter(...) | a template value loaded from a remote source. |
132148| VelocitySSTI.java:77:21:77:27 | context | VelocitySSTI.java:69:17:69:44 | getParameter(...) : String | VelocitySSTI.java:77:21:77:27 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:69:17:69:44 | getParameter(...) | a template value loaded from a remote source. |
133- | VelocitySSTI.java:89:60:89:66 | context | VelocitySSTI.java:83:17:83:44 | getParameter(...) : String | VelocitySSTI.java:89:60:89:66 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:83:17:83:44 | getParameter(...) | a template value loaded from a remote source. |
134- | VelocitySSTI.java:102 :11:102 :17 | context | VelocitySSTI.java:95 :17:95 :44 | getParameter(...) : String | VelocitySSTI.java:102 :11:102 :17 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:95 :17:95 :44 | getParameter(...) | a template value loaded from a remote source. |
135- | VelocitySSTI.java:115 :11:115 :17 | context | VelocitySSTI.java:108 :17:108 :44 | getParameter(...) : String | VelocitySSTI.java:115 :11:115 :17 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:108 :17:108 :44 | getParameter(...) | a template value loaded from a remote source. |
136- | VelocitySSTI.java:123 :37:123 :40 | code | VelocitySSTI.java:120 :17:120 :44 | getParameter(...) : String | VelocitySSTI.java:123 :37:123 :40 | code | Potential arbitrary code execution due to $@. | VelocitySSTI.java:120 :17:120 :44 | getParameter(...) | a template value loaded from a remote source. |
149+ | VelocitySSTI.java:90:52:90:58 | context | VelocitySSTI.java:83:17:83:44 | getParameter(...) : String | VelocitySSTI.java:90:52:90:58 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:83:17:83:44 | getParameter(...) | a template value loaded from a remote source. |
150+ | VelocitySSTI.java:103 :11:103 :17 | context | VelocitySSTI.java:96 :17:96 :44 | getParameter(...) : String | VelocitySSTI.java:103 :11:103 :17 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:96 :17:96 :44 | getParameter(...) | a template value loaded from a remote source. |
151+ | VelocitySSTI.java:116 :11:116 :17 | context | VelocitySSTI.java:109 :17:109 :44 | getParameter(...) : String | VelocitySSTI.java:116 :11:116 :17 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:109 :17:109 :44 | getParameter(...) | a template value loaded from a remote source. |
152+ | VelocitySSTI.java:124 :37:124 :40 | code | VelocitySSTI.java:121 :17:121 :44 | getParameter(...) : String | VelocitySSTI.java:124 :37:124 :40 | code | Potential arbitrary code execution due to $@. | VelocitySSTI.java:121 :17:121 :44 | getParameter(...) | a template value loaded from a remote source. |
0 commit comments