Skip to content

Commit 327dab6

Browse files
committed
Java: Opt-in the tainted permissions check query to threat models.
1 parent 1d1a849 commit 327dab6

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

java/ql/lib/semmle/code/java/security/TaintedPermissionsCheckQuery.qll

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ private class WildCardPermissionConstruction extends ClassInstanceExpr, Permissi
5454
* A configuration for tracking flow from user input to a permissions check.
5555
*/
5656
module TaintedPermissionsCheckFlowConfig implements DataFlow::ConfigSig {
57-
predicate isSource(DataFlow::Node source) { source instanceof UserInput }
57+
predicate isSource(DataFlow::Node source) { source instanceof ThreatModelFlowSource }
5858

5959
predicate isSink(DataFlow::Node sink) {
6060
sink.asExpr() = any(PermissionsConstruction p).getInput()

0 commit comments

Comments
 (0)