Skip to content

Commit 2c54996

Browse files
authored
Apply @jcogs33's suggestions from code review
1 parent a48fa65 commit 2c54996

File tree

2 files changed

+2
-1
lines changed

2 files changed

+2
-1
lines changed

java/ql/lib/ext/org.springframework.jdbc.core.namedparam.model.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,6 @@ extensions:
44
extensible: sinkModel
55
data:
66
- ["org.springframework.jdbc.core.namedparam", "NamedParameterJdbcOperations", True, "batchUpdate", "", "", "Argument[0]", "sql", "manual"]
7-
- ["org.springframework.jdbc.core.namedparam", "NamedParameterJdbcOperations", True, "batchUpdate", "(String[])", "", "Argument[0]", "sql", "manual"]
87
- ["org.springframework.jdbc.core.namedparam", "NamedParameterJdbcOperations", True, "execute", "", "", "Argument[0]", "sql", "manual"]
98
- ["org.springframework.jdbc.core.namedparam", "NamedParameterJdbcOperations", True, "query", "", "", "Argument[0]", "sql", "manual"]
109
- ["org.springframework.jdbc.core.namedparam", "NamedParameterJdbcOperations", True, "queryForList", "", "", "Argument[0]", "sql", "manual"]

java/ql/test/query-tests/security/CWE-089/semmle/examples/SpringJdbc.java

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -62,6 +62,8 @@ public static void test(JdbcTemplate template, NamedParameterJdbcOperations name
6262
namedParamTemplate.query(source(), (RowCallbackHandler) null); // $ sqlInjection
6363
namedParamTemplate.queryForList(source(), (Map<String, ?>) null); // $ sqlInjection
6464
namedParamTemplate.queryForList(source(), (Map<String, ?>) null, (Class) null); // $ sqlInjection
65+
namedParamTemplate.queryForList(source(), (SqlParameterSource) null); // $ sqlInjection
66+
namedParamTemplate.queryForList(source(), (SqlParameterSource) null, (Class) null); // $ sqlInjection
6567
namedParamTemplate.queryForMap(source(), (Map<String, ?>) null); // $ sqlInjection
6668
namedParamTemplate.queryForMap(source(), (SqlParameterSource) null); // $ sqlInjection
6769
namedParamTemplate.queryForObject(source(), (Map<String, ?>) null, (Class) null); // $ sqlInjection

0 commit comments

Comments
 (0)