Skip to content

Commit 48b50f9

Browse files
Update java/ql/src/semmle/code/java/frameworks/jackson/JacksonSerializability.qll
Co-authored-by: Tony Torralba <[email protected]>
1 parent 5a68ac8 commit 48b50f9

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

java/ql/src/semmle/code/java/frameworks/jackson/JacksonSerializability.qll

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,10 @@ private class JacksonWriteValueMethod extends Method, TaintPreservingCallable {
5353

5454
private class JacksonReadValueMethod extends Method, TaintPreservingCallable {
5555
JacksonReadValueMethod() {
56-
getDeclaringType().hasQualifiedName("com.fasterxml.jackson.databind", "ObjectReader") and
56+
(
57+
getDeclaringType().hasQualifiedName("com.fasterxml.jackson.databind", "ObjectReader") or
58+
getDeclaringType().hasQualifiedName("com.fasterxml.jackson.databind", "ObjectMapper")
59+
) and
5760
hasName(["readValue", "readValues"])
5861
}
5962

0 commit comments

Comments
 (0)