Skip to content

Commit 646254c

Browse files
committed
Add credentials sinks from SensitiveApi
1 parent 057a74d commit 646254c

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

java/ql/lib/semmle/code/java/security/WeakRandomnessQuery.qll

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
import java
44
private import semmle.code.java.frameworks.Servlets
55
private import semmle.code.java.security.SensitiveActions
6+
private import semmle.code.java.security.SensitiveApi
67
private import semmle.code.java.dataflow.TaintTracking
78
private import semmle.code.java.dataflow.ExternalFlow
89
private import semmle.code.java.security.RandomQuery
@@ -66,6 +67,8 @@ private class CryptographicSink extends WeakRandomnessSink {
6667
CryptographicSink() { sinkNode(this, "crypto-parameter") }
6768
}
6869

70+
private class CredentialsSink extends WeakRandomnessSink instanceof CredentialsSinkNode { }
71+
6972
/**
7073
* Holds if there is a method access which converts `bytes` to the string `str`.
7174
*/

0 commit comments

Comments
 (0)