Skip to content

Commit aa9d848

Browse files
author
edvraa
committed
Rename taint tracking variables
1 parent 7cbbd6c commit aa9d848

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

csharp/ql/src/Security Features/CWE-502/UnsafeDeserialization.ql

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -17,11 +17,11 @@ from Call deserializeCall, InstanceMethodSink sink
1717
where
1818
deserializeCall.getAnArgument() = sink.asExpr() and
1919
not exists(
20-
DataFlow::PathNode constructor, DataFlow::PathNode usage,
21-
SafeConstructorTrackingConfig constructorTracking
20+
SafeConstructorTrackingConfig safeConstructorTracking, DataFlow::PathNode safeCreation,
21+
DataFlow::PathNode safeTypeUsage
2222
|
23-
constructorTracking.hasFlowPath(constructor, usage) and
24-
usage.getNode().asExpr().getParent() = deserializeCall
23+
safeConstructorTracking.hasFlowPath(safeCreation, safeTypeUsage) and
24+
safeTypeUsage.getNode().asExpr().getParent() = deserializeCall
2525
)
2626
or
2727
exists(ConstructorOrStaticMethodSink sink2 | deserializeCall.getAnArgument() = sink2.asExpr())

0 commit comments

Comments
 (0)