Skip to content

Commit 5480a31

Browse files
committed
Java: Remove MultipartFile.getSize/isEmpty from remote flow sources
1 parent 0d405c2 commit 5480a31

File tree

2 files changed

+0
-3
lines changed

2 files changed

+0
-3
lines changed

java/ql/src/semmle/code/java/dataflow/ExternalFlow.qll

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -110,8 +110,6 @@ private predicate sourceModelCsv(string row) {
110110
"org.springframework.web.multipart;MultipartFile;true;getName;();;ReturnValue;remote",
111111
"org.springframework.web.multipart;MultipartFile;true;getOriginalFilename;();;ReturnValue;remote",
112112
"org.springframework.web.multipart;MultipartFile;true;getResource;();;ReturnValue;remote",
113-
"org.springframework.web.multipart;MultipartFile;true;getSize;();;ReturnValue;remote",
114-
"org.springframework.web.multipart;MultipartFile;true;isEmpty;();;ReturnValue;remote",
115113
// HttpServletRequest.get*
116114
"javax.servlet.http;HttpServletRequest;false;getHeader;(String);;ReturnValue;remote",
117115
"javax.servlet.http;HttpServletRequest;false;getHeaders;(String);;ReturnValue;remote",

java/ql/test/library-tests/dataflow/taintsources/remote.expected

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,6 @@
3636
| RmiFlowImpl.java:4:30:4:40 | path | RmiFlowImpl.java:5:28:5:31 | path |
3737
| RmiFlowImpl.java:4:30:4:40 | path | RmiFlowImpl.java:6:29:6:35 | command |
3838
| SpringMultiPart.java:8:3:8:17 | getBytes(...) | SpringMultiPart.java:8:3:8:17 | getBytes(...) |
39-
| SpringMultiPart.java:9:3:9:16 | isEmpty(...) | SpringMultiPart.java:9:3:9:16 | isEmpty(...) |
4039
| SpringMultiPart.java:10:3:10:23 | getInputStream(...) | SpringMultiPart.java:10:3:10:23 | getInputStream(...) |
4140
| SpringMultiPart.java:11:3:11:20 | getResource(...) | SpringMultiPart.java:11:3:11:20 | getResource(...) |
4241
| SpringMultiPart.java:12:3:12:16 | getName(...) | SpringMultiPart.java:12:3:12:16 | getName(...) |

0 commit comments

Comments
 (0)