Skip to content

Commit 7859288

Browse files
ahmed-farid-devsmowton
authored andcommitted
Update TimingAttackAgainstHeader.ql
1 parent d83444c commit 7859288

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

java/ql/src/experimental/Security/CWE/CWE-208/TimingAttackAgainstHeader.ql

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,7 @@ import semmle.code.java.dataflow.FlowSources
1616
import semmle.code.java.dataflow.TaintTracking
1717
import DataFlow::PathGraph
1818

19+
/** A static method that uses a non-constant-time algorithm for comparing inputs. */
1920
private class NonConstantTimeComparisonCall extends StaticMethodAccess {
2021
NonConstantTimeComparisonCall() {
2122
this.getMethod()
@@ -24,6 +25,7 @@ private class NonConstantTimeComparisonCall extends StaticMethodAccess {
2425
}
2526
}
2627

28+
/** Methods that use a non-constant-time algorithm for comparing inputs. */
2729
private class NonConstantTimeEqualsCall extends MethodAccess {
2830
NonConstantTimeEqualsCall() {
2931
this.getMethod().hasQualifiedName("java.lang", "String", ["equals", "contentEquals", "equalsIgnoreCase"])

0 commit comments

Comments
 (0)