Skip to content

Commit ba3c38c

Browse files
committed
Restrict addCookie to specific interface
1 parent dc3e4cd commit ba3c38c

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

java/ql/lib/semmle/code/java/security/WeakRandomnessQuery.qll

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,9 @@ abstract class WeakRandomnessSink extends DataFlow::Node { }
5757
private class CookieSink extends WeakRandomnessSink {
5858
CookieSink() {
5959
this.getType() instanceof TypeCookie and
60-
exists(MethodAccess ma | ma.getMethod().hasName("addCookie") |
60+
exists(MethodAccess ma |
61+
ma.getMethod().hasQualifiedName("javax.servlet.http", "HttpServletResponse", "addCookie")
62+
|
6163
ma.getArgument(0) = this.asExpr()
6264
)
6365
}

0 commit comments

Comments
 (0)