Skip to content

Commit 4529d8b

Browse files
committed
Add support for log injection in MaD
1 parent 40eab18 commit 4529d8b

File tree

2 files changed

+8
-0
lines changed

2 files changed

+8
-0
lines changed
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
---
2+
category: minorAnalysis
3+
---
4+
* Added support for Model as Data for Log-injection query

javascript/ql/lib/semmle/javascript/security/dataflow/LogInjectionQuery.qll

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -66,3 +66,7 @@ class HtmlSanitizer extends Sanitizer instanceof HtmlSanitizerCall { }
6666
class JsonStringifySanitizer extends Sanitizer {
6767
JsonStringifySanitizer() { this = any(JsonStringifyCall c).getOutput() }
6868
}
69+
70+
private class SinkFromModel extends Sink {
71+
SinkFromModel() { this = ModelOutput::getASinkNode("log-injection").asSink() }
72+
}

0 commit comments

Comments
 (0)