Skip to content

Commit 4bfd34b

Browse files
committed
Moved from experimental
1 parent 38e0524 commit 4bfd34b

File tree

12 files changed

+7
-6
lines changed

12 files changed

+7
-6
lines changed

java/ql/src/experimental/Security/CWE/CWE-094/JexlInjection.ql renamed to java/ql/src/Security/CWE/CWE-094/JexlInjection.ql

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,8 @@
1313
import java
1414
import JexlInjectionLib
1515
import DataFlow::PathGraph
16-
import FlowUtils
16+
import semmle.code.java.dataflow.FlowSources
17+
//import FlowUtils
1718

1819
/**
1920
* A taint-tracking configuration for unsafe user input
@@ -28,8 +29,8 @@ class JexlInjectionConfig extends TaintTracking::Configuration {
2829
override predicate isSink(DataFlow::Node sink) { sink instanceof JexlEvaluationSink }
2930

3031
override predicate isAdditionalTaintStep(DataFlow::Node node1, DataFlow::Node node2) {
31-
any(JexlInjectionAdditionalTaintStep c).step(node1, node2) or
32-
hasGetterFlow(node1, node2)
32+
any(JexlInjectionAdditionalTaintStep c).step(node1, node2) /*or
33+
hasGetterFlow(node1, node2)*/
3334
}
3435
}
3536

java/ql/test/experimental/query-tests/security/CWE-094/JexlInjection.qlref

Lines changed: 0 additions & 1 deletion
This file was deleted.
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,2 @@
1-
//semmle-extractor-options: --javac-args -cp ${testdir}/../../../../stubs/springframework-5.2.3:${testdir}/../../../../stubs/mvel2-2.4.7:${testdir}/../../../../stubs/jsr223-api:${testdir}/../../../../stubs/apache-commons-jexl-2.1.1:${testdir}/../../../../stubs/apache-commons-jexl-3.1:${testdir}/../../../../stubs/scriptengine:${testdir}/../../../../stubs/java-ee-el:${testdir}/../../../../stubs/juel-2.2:${testdir}/../../../stubs/groovy-all-3.0.7:${testdir}/../../../../stubs/servlet-api-2.4:${testdir}/../../../../stubs/apache-commons-logging-1.2
1+
//semmle-extractor-options: --javac-args -cp ${testdir}/../../../../stubs/springframework-5.2.3:${testdir}/../../../../stubs/mvel2-2.4.7:${testdir}/../../../../stubs/jsr223-api:${testdir}/../../../../stubs/scriptengine:${testdir}/../../../../stubs/java-ee-el:${testdir}/../../../../stubs/juel-2.2:${testdir}/../../../stubs/groovy-all-3.0.7:${testdir}/../../../../stubs/servlet-api-2.4
22

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
Security/CWE/CWE-094/JexlInjection.ql

0 commit comments

Comments
 (0)