Skip to content

Commit 85b3092

Browse files
committed
Add security-severity and fix alert message
1 parent d72d096 commit 85b3092

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

swift/ql/src/queries/Security/CWE-943/PredicateInjection.ql

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
* changing the predicate's intended logic.
55
* @kind path-problem
66
* @problem.severity error
7+
* @security-severity 8.8
78
* @precision high
89
* @id swift/predicate-injection
910
* @tags security
@@ -17,4 +18,5 @@ import DataFlow::PathGraph
1718

1819
from DataFlow::PathNode source, DataFlow::PathNode sink
1920
where any(PredicateInjectionConf c).hasFlowPath(source, sink)
20-
select sink.getNode(), source, sink, "$@", source.getNode(), ""
21+
select sink.getNode(), source, sink, "This predicate depends on a $@.", source.getNode(),
22+
"user-provided value"

0 commit comments

Comments
 (0)