Skip to content

Commit a046d75

Browse files
committed
Apply suggestions from code review
1 parent 452fd9a commit a046d75

File tree

4 files changed

+3
-5
lines changed

4 files changed

+3
-5
lines changed

java/ql/src/Security/CWE/CWE-347/MissingJWTSignatureCheck.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
/**
22
* @name Missing JWT signature check
3-
* @description Failing to check the JWT signature may allow an attacker to forge their own tokens.
3+
* @description Failing to check the Json Web Token (JWT) signature may allow an attacker to forge their own tokens.
44
* @kind path-problem
55
* @problem.severity error
66
* @security-severity 7.8

java/ql/src/semmle/code/java/dataflow/ExternalFlow.qll

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -97,7 +97,6 @@ private module Frameworks {
9797
private import semmle.code.java.security.ResponseSplitting
9898
private import semmle.code.java.security.InformationLeak
9999
private import semmle.code.java.security.JexlInjectionSinkModels
100-
private import semmle.code.java.security.JWT
101100
private import semmle.code.java.security.LdapInjection
102101
private import semmle.code.java.security.XPath
103102
private import semmle.code.java.frameworks.android.SQLite

java/ql/src/semmle/code/java/security/JWT.qll

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
/** Provides classes for working with JWT libraries. */
1+
/** Provides classes for working with JSON Web Token (JWT) libraries. */
22

33
import java
44
private import semmle.code.java.dataflow.ExternalFlow

java/ql/src/semmle/code/java/security/MissingJWTSignatureCheckQuery.qll

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,7 @@
1-
/** Provides classes to be used in queries related to JWT signature vulnerabilities. */
1+
/** Provides classes to be used in queries related to JSON Web Token (JWT) signature vulnerabilities. */
22

33
import java
44
import semmle.code.java.dataflow.DataFlow
5-
import semmle.code.java.dataflow.ExternalFlow
65
import semmle.code.java.security.JWT
76

87
/**

0 commit comments

Comments
 (0)