Skip to content

Commit 1caa5c4

Browse files
committed
Adjust hostname verifier sink identifier name
1 parent 6c78a24 commit 1caa5c4

File tree

2 files changed

+3
-3
lines changed

2 files changed

+3
-3
lines changed

java/ql/src/Security/CWE/CWE-297/UnsafeHostnameVerification.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ class TrustAllHostnameVerifierConfiguration extends DataFlow::Configuration {
5050
source.asExpr().(ClassInstanceExpr).getConstructedType() instanceof TrustAllHostnameVerifier
5151
}
5252

53-
override predicate isSink(DataFlow::Node sink) { sinkNode(sink, "set-hostname") }
53+
override predicate isSink(DataFlow::Node sink) { sinkNode(sink, "set-hostname-verifier") }
5454

5555
override predicate isBarrier(DataFlow::Node barrier) {
5656
// ignore nodes that are in functions that intentionally disable hostname verification

java/ql/src/semmle/code/java/dataflow/ExternalFlow.qll

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -209,8 +209,8 @@ private predicate sinkModelCsv(string row) {
209209
// Bean validation
210210
"javax.validation;ConstraintValidatorContext;true;buildConstraintViolationWithTemplate;;;Argument[0];bean-validation",
211211
// Set hostname
212-
"javax.net.ssl;HttpsURLConnection;true;setDefaultHostnameVerifier;;;Argument[0];set-hostname",
213-
"javax.net.ssl;HttpsURLConnection;true;setHostnameVerifier;;;Argument[0];set-hostname"
212+
"javax.net.ssl;HttpsURLConnection;true;setDefaultHostnameVerifier;;;Argument[0];set-hostname-verifier",
213+
"javax.net.ssl;HttpsURLConnection;true;setHostnameVerifier;;;Argument[0];set-hostname-verifier"
214214
]
215215
}
216216

0 commit comments

Comments
 (0)