@@ -241,7 +241,30 @@ private predicate summaryModelCsv(string row) {
241
241
"org.apache.commons.io;IOUtils;false;write;;;Argument[0];Argument[1];taint" ,
242
242
"org.apache.commons.io;IOUtils;false;writeChunked;;;Argument[0];Argument[1];taint" ,
243
243
"org.apache.commons.io;IOUtils;false;writeLines;;;Argument[0];Argument[2];taint" ,
244
- "org.apache.commons.io;IOUtils;false;writeLines;;;Argument[1];Argument[2];taint"
244
+ "org.apache.commons.io;IOUtils;false;writeLines;;;Argument[1];Argument[2];taint" ,
245
+ // constructor flow
246
+ "java.io;File;false;File;;;Argument[0];ReturnValue;taint" ,
247
+ "java.io;File;false;File;;;Argument[1];ReturnValue;taint" ,
248
+ "java.net;URI;false;URI;(String);;Argument[0];ReturnValue;taint" ,
249
+ "javax.xml.transform.stream;StreamSource;false;StreamSource;;;Argument[0];ReturnValue;taint" ,
250
+ "javax.xml.transform.sax;SAXSource;false;SAXSource;(InputSource);;Argument[0];ReturnValue;taint" ,
251
+ "javax.xml.transform.sax;SAXSource;false;SAXSource;(XMLReader,InputSource);;Argument[1];ReturnValue;taint" ,
252
+ "org.xml.sax;InputSource;false;InputSource;;;Argument[0];ReturnValue;taint" ,
253
+ "javax.servlet.http;Cookie;false;Cookie;;;Argument[0];ReturnValue;taint" ,
254
+ "javax.servlet.http;Cookie;false;Cookie;;;Argument[1];ReturnValue;taint" ,
255
+ "java.util.zip;ZipInputStream;false;ZipInputStream;;;Argument[0];ReturnValue;taint" ,
256
+ "java.util.zip;GZIPInputStream;false;GZIPInputStream;;;Argument[0];ReturnValue;taint" ,
257
+ "java.util;StringTokenizer;false;StringTokenizer;;;Argument[0];ReturnValue;taint" ,
258
+ "java.beans;XMLDecoder;false;XMLDecoder;;;Argument[0];ReturnValue;taint" ,
259
+ "com.esotericsoftware.kryo.io;Input;false;Input;;;Argument[0];ReturnValue;taint" ,
260
+ "java.io;BufferedInputStream;false;BufferedInputStream;;;Argument[0];ReturnValue;taint" ,
261
+ "java.io;DataInputStream;false;DataInputStream;;;Argument[0];ReturnValue;taint" ,
262
+ "java.io;ByteArrayInputStream;false;ByteArrayInputStream;;;Argument[0];ReturnValue;taint" ,
263
+ "java.io;ObjectInputStream;false;ObjectInputStream;;;Argument[0];ReturnValue;taint" ,
264
+ "java.io;StringReader;false;StringReader;;;Argument[0];ReturnValue;taint" ,
265
+ "java.io;CharArrayReader;false;CharArrayReader;;;Argument[0];ReturnValue;taint" ,
266
+ "java.io;BufferedReader;false;BufferedReader;;;Argument[0];ReturnValue;taint" ,
267
+ "java.io;InputStreamReader;false;InputStreamReader;;;Argument[0];ReturnValue;taint"
245
268
]
246
269
}
247
270
0 commit comments