Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit ee6d28b

Browse files
Use LocalUserInput when looking for JEXL injections
1 parent 8166e26 commit ee6d28b

1 file changed

Lines changed: 1 addition & 2 deletions

File tree

java/ql/src/experimental/Security/CWE/CWE-094/JexlInjectionLib.qll

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,7 @@ class JexlInjectionConfig extends TaintTracking::Configuration {
1313
override predicate isSource(DataFlow::Node source) {
1414
source instanceof TaintedSpringRequestBody or
1515
source instanceof RemoteFlowSource or
16-
source instanceof UserInput or
17-
source instanceof EnvInput
16+
source instanceof LocalUserInput
1817
}
1918

2019
override predicate isSink(DataFlow::Node sink) { sink instanceof JexlEvaluationSink }

0 commit comments

Comments
 (0)