Skip to content

Commit 9b1c54e

Browse files
committed
Add argument indices to HTTP header splitting sinks
1 parent 180904e commit 9b1c54e

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

java/ql/src/semmle/code/java/security/ResponseSplitting.qll

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,8 +17,8 @@ private class HeaderSplittingSinkModel extends SinkModelCsv {
1717
row =
1818
[
1919
"javax.servlet.http;HttpServletResponse;false;addCookie;;;Argument[0];header-splitting",
20-
"javax.servlet.http;HttpServletResponse;false;addHeader;;;Argument;header-splitting",
21-
"javax.servlet.http;HttpServletResponse;false;setHeader;;;Argument;header-splitting",
20+
"javax.servlet.http;HttpServletResponse;false;addHeader;;;Argument[0..1];header-splitting",
21+
"javax.servlet.http;HttpServletResponse;false;setHeader;;;Argument[0..1];header-splitting",
2222
"javax.ws.rs.core;ResponseBuilder;false;header;;;Argument[1];header-splitting"
2323
]
2424
}

0 commit comments

Comments
 (0)