Skip to content

Commit b8f9b2b

Browse files
Update TimingAttackAgainstHeaderValue.ql
1 parent 016136a commit b8f9b2b

File tree

1 file changed

+1
-7
lines changed

1 file changed

+1
-7
lines changed

python/ql/src/experimental/Security/CWE-208/TimingAttackAgainstHeaderValue/TimingAttackAgainstHeaderValue.ql

Lines changed: 1 addition & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -24,13 +24,7 @@ class ClientSuppliedSecretConfig extends TaintTracking::Configuration {
2424

2525
override predicate isSource(DataFlow::Node source) { source instanceof ClientSuppliedSecret }
2626

27-
override predicate isSink(DataFlow::Node sink) {
28-
exists(Compare cmp, Expr left, Expr right, Cmpop cmpop |
29-
cmpop.getSymbol() = ["==", "in", "is not", "!="] and
30-
cmp.compares(left, cmpop, right) and
31-
sink.asExpr() = [left, right]
32-
)
33-
}
27+
override predicate isSink(DataFlow::Node sink) { sink instanceof CompareSink }
3428
}
3529

3630
from ClientSuppliedSecretConfig config, DataFlow::PathNode source, DataFlow::PathNode sink

0 commit comments

Comments
 (0)