diff --git a/java/ql/lib/ext/struts2.model.yml b/java/ql/lib/ext/struts2.model.yml index bf49066bd67e..db05fd9f7451 100644 --- a/java/ql/lib/ext/struts2.model.yml +++ b/java/ql/lib/ext/struts2.model.yml @@ -37,6 +37,7 @@ extensions: - ["com.opensymphony.xwork2.util", "TextParseUtil", true, "translateVariablesCollection", "(char[],String,ValueStack,boolean,TextParseUtil$ParsedValueEvaluator,int)", "", "Argument[1]", "ognl-injection", "manual"] - ["com.opensymphony.xwork2", "ActionSupport", true, "getFormatted", "(String,String)", "", "Argument[0]", "ognl-injection", "manual"] - ["com.opensymphony.xwork2", "ActionSupport", true, "getFormatted", "(String,String)", "", "Argument[1]", "ognl-injection", "manual"] + - ["com.opensymphony.xwork2", "ActionSupport", False, "getText", "(String)", "", "Argument[0]", "ognl-injection", "manual"] - ["com.opensymphony.xwork2", "TextProvider", true, "getText", "(String)", "", "Argument[0]", "ognl-injection", "manual"] - ["com.opensymphony.xwork2", "TextProvider", true, "getText", "(String,List)", "", "Argument[0]", "ognl-injection", "manual"] - ["com.opensymphony.xwork2", "TextProvider", true, "getText", "(String,String)", "", "Argument[0]", "ognl-injection", "manual"] diff --git a/java/ql/src/change-notes/2025-08-25-ognl-additional-sink.md b/java/ql/src/change-notes/2025-08-25-ognl-additional-sink.md new file mode 100644 index 000000000000..8aa3e9f36f2e --- /dev/null +++ b/java/ql/src/change-notes/2025-08-25-ognl-additional-sink.md @@ -0,0 +1,4 @@ +--- +category: minorAnalysis +--- +* Add sink related to `com.opensymphony.xwork2.TextProvider.getText` from the query `java/ognl-injection`. \ No newline at end of file