Skip to content

Commit ab1bc68

Browse files
committed
add CWE-80 to queries that detect bad HTML sanitizers
1 parent 7af6dc7 commit ab1bc68

File tree

3 files changed

+6
-3
lines changed

3 files changed

+6
-3
lines changed

javascript/ql/src/Security/CWE-116/BadTagFilter.ql

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,9 @@
88
* @id js/bad-tag-filter
99
* @tags correctness
1010
* security
11-
* external/cwe/cwe-116
1211
* external/cwe/cwe-020
12+
* external/cwe/cwe-080
13+
* external/cwe/cwe-116
1314
* external/cwe/cwe-185
1415
* external/cwe/cwe-186
1516
*/

javascript/ql/src/Security/CWE-116/IncompleteMultiCharacterSanitization.ql

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,8 +8,9 @@
88
* @id js/incomplete-multi-character-sanitization
99
* @tags correctness
1010
* security
11-
* external/cwe/cwe-116
1211
* external/cwe/cwe-020
12+
* external/cwe/cwe-080
13+
* external/cwe/cwe-116
1314
*/
1415

1516
import javascript

javascript/ql/src/Security/CWE-116/IncompleteSanitization.ql

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,8 +9,9 @@
99
* @id js/incomplete-sanitization
1010
* @tags correctness
1111
* security
12-
* external/cwe/cwe-116
1312
* external/cwe/cwe-020
13+
* external/cwe/cwe-080
14+
* external/cwe/cwe-116
1415
*/
1516

1617
import javascript

0 commit comments

Comments
 (0)