Skip to content

checker: request tainted file write and request tainted HttpResponse/HttpResponseBadRequest#172

Merged
sourya-deepsource merged 2 commits intoDeepSourceCorp:masterfrom
MashyBasker:checkers/django-user-tainted-data-pass
Mar 21, 2025
Merged

checker: request tainted file write and request tainted HttpResponse/HttpResponseBadRequest#172
sourya-deepsource merged 2 commits intoDeepSourceCorp:masterfrom
MashyBasker:checkers/django-user-tainted-data-pass

Conversation

@MashyBasker
Copy link
Contributor

Purpose

This PR adds checker for the following:

  • file.write() method call tainted with dynamic data from a request call
  • HttpResponse and HttpResponseBadRequest tainted with dynamic data from request call

…uest

Signed-off-by: Maharshi Basu <basumaharshi10@gmail.com>
@vercel
Copy link

vercel bot commented Mar 19, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

1 Skipped Deployment
Name Status Preview Comments Updated (UTC)
globstar ⬜️ Ignored (Inspect) Visit Preview Mar 21, 2025 2:51pm

Signed-off-by: Sourya Vatsyayan <sourya@deepsource.io>
@sourya-deepsource sourya-deepsource merged commit 0dbdffb into DeepSourceCorp:master Mar 21, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants