Skip to content

Commit e97bad3

Browse files
committed
Support field access data flow for JacksonDeserializedTaintStep
1 parent 83d527e commit e97bad3

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

java/ql/src/semmle/code/java/frameworks/jackson/JacksonSerializability.qll

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -167,7 +167,7 @@ class JacksonDeserializableFieldAccess extends FieldAccess {
167167
*/
168168
class JacksonDeserializedTaintStep extends AdditionalTaintStep {
169169
override predicate step(DataFlow::Node node1, DataFlow::Node node2) {
170-
node2.asExpr().(JacksonDeserializableFieldAccess).getQualifier() = node1.asExpr()
170+
DataFlow::getFieldQualifier(node2.asExpr().(JacksonDeserializableFieldAccess)) = node1
171171
}
172172
}
173173

0 commit comments

Comments
 (0)