File tree Expand file tree Collapse file tree 4 files changed +3
-5
lines changed Expand file tree Collapse file tree 4 files changed +3
-5
lines changed Original file line number Diff line number Diff line change 1
1
/**
2
2
* @name Missing JWT signature check
3
- * @description Failing to check the JWT signature may allow an attacker to forge their own tokens.
3
+ * @description Failing to check the Json Web Token ( JWT) signature may allow an attacker to forge their own tokens.
4
4
* @kind path-problem
5
5
* @problem.severity error
6
6
* @security-severity 7.8
Original file line number Diff line number Diff line change @@ -97,7 +97,6 @@ private module Frameworks {
97
97
private import semmle.code.java.security.ResponseSplitting
98
98
private import semmle.code.java.security.InformationLeak
99
99
private import semmle.code.java.security.JexlInjectionSinkModels
100
- private import semmle.code.java.security.JWT
101
100
private import semmle.code.java.security.LdapInjection
102
101
private import semmle.code.java.security.XPath
103
102
private import semmle.code.java.frameworks.android.SQLite
Original file line number Diff line number Diff line change 1
- /** Provides classes for working with JWT libraries. */
1
+ /** Provides classes for working with JSON Web Token ( JWT) libraries. */
2
2
3
3
import java
4
4
private import semmle.code.java.dataflow.ExternalFlow
Original file line number Diff line number Diff line change 1
- /** Provides classes to be used in queries related to JWT signature vulnerabilities. */
1
+ /** Provides classes to be used in queries related to JSON Web Token ( JWT) signature vulnerabilities. */
2
2
3
3
import java
4
4
import semmle.code.java.dataflow.DataFlow
5
- import semmle.code.java.dataflow.ExternalFlow
6
5
import semmle.code.java.security.JWT
7
6
8
7
/**
You can’t perform that action at this time.
0 commit comments