Skip to content

Commit 7d4767a

Browse files
committed
Java insecure cookies query: look through named constants
1 parent 3719875 commit 7d4767a

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

java/ql/src/Security/CWE/CWE-614/InsecureCookie.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ where
2020
not exists(Variable cookie, MethodAccess m |
2121
add.getArgument(0) = cookie.getAnAccess() and
2222
m.getMethod().getName() = "setSecure" and
23-
m.getArgument(0).(BooleanLiteral).getBooleanValue() = true and
23+
m.getArgument(0).(CompileTimeConstantExpr).getBooleanValue() = true and
2424
m.getQualifier() = cookie.getAnAccess()
2525
)
2626
select add, "Cookie is added to response without the 'secure' flag being set."

0 commit comments

Comments
 (0)