Skip to content

Commit b3b139b

Browse files
committed
1 parent 45b627d commit b3b139b

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

java/ql/lib/semmle/code/java/security/SqlConcatenatedQuery.qll

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,15 @@ module UncontrolledStringBuilderSourceFlowConfig implements DataFlow::ConfigSig
2424
predicate isSink(DataFlow::Node sink) { sink instanceof QueryInjectionSink }
2525

2626
predicate isBarrier(DataFlow::Node node) { node instanceof SimpleTypeSanitizer }
27+
28+
predicate observeDiffInformedIncrementalMode() { any() }
29+
30+
Location getASelectedSourceLocation(DataFlow::Node source) {
31+
exists(Expr uncontrolled, StringBuilderVar sbv | result = uncontrolled.getLocation() |
32+
uncontrolledStringBuilderQuery(sbv, uncontrolled) and
33+
source = DataFlow::exprNode(sbv.getToStringCall())
34+
)
35+
}
2736
}
2837

2938
/**

0 commit comments

Comments
 (0)