Skip to content

Commit e1d30eb

Browse files
committed
Added severity
Removed duplicated code
1 parent ec8ffee commit e1d30eb

File tree

2 files changed

+1
-3
lines changed

2 files changed

+1
-3
lines changed

java/ql/lib/semmle/code/java/security/IntentUriPermissionManipulation.qll

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -51,9 +51,6 @@ private class IntentFlagsOrDataChangedSanitizer extends IntentUriPermissionManip
5151
TaintTracking::localExprTaint(any(GrantWriteUriPermissionFlag f).getAnAccess(),
5252
ma.getArgument(0))
5353
or
54-
ma.getMethod() = m and
55-
m.getDeclaringType() instanceof TypeIntent and
56-
this.asExpr() = ma.getQualifier() and
5754
m.hasName("setFlags") and
5855
not TaintTracking::localExprTaint(any(GrantUriPermissionFlag f).getAnAccess(),
5956
ma.getArgument(0))

java/ql/src/Security/CWE/CWE-266/IntentUriPermissionManipulation.ql

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@
55
* arbitrary Content Providers that are accessible by the vulnerable application.
66
* @kind path-problem
77
* @problem.severity error
8+
* @security-severity 7.8
89
* @precision high
910
* @id java/android/intent-uri-permission-manipulation
1011
* @tags security

0 commit comments

Comments
 (0)