Skip to content

Commit 55be2e5

Browse files
Jami CogswellJami Cogswell
authored andcommitted
Java: update url-redirect sink kind to url-redirection
1 parent d24d8b1 commit 55be2e5

File tree

6 files changed

+8
-8
lines changed

6 files changed

+8
-8
lines changed

java/ql/lib/ext/jakarta.ws.rs.core.model.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@ extensions:
33
pack: codeql/java-all
44
extensible: sinkModel
55
data:
6-
- ["jakarta.ws.rs.core", "Response", True, "seeOther", "", "", "Argument[0]", "url-redirect", "manual"]
7-
- ["jakarta.ws.rs.core", "Response", True, "temporaryRedirect", "", "", "Argument[0]", "url-redirect", "manual"]
6+
- ["jakarta.ws.rs.core", "Response", True, "seeOther", "", "", "Argument[0]", "url-redirection", "manual"]
7+
- ["jakarta.ws.rs.core", "Response", True, "temporaryRedirect", "", "", "Argument[0]", "url-redirection", "manual"]
88
- addsTo:
99
pack: codeql/java-all
1010
extensible: summaryModel

java/ql/lib/ext/javax.ws.rs.core.model.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@ extensions:
33
pack: codeql/java-all
44
extensible: sinkModel
55
data:
6-
- ["javax.ws.rs.core", "Response", True, "seeOther", "", "", "Argument[0]", "url-redirect", "manual"]
7-
- ["javax.ws.rs.core", "Response", True, "temporaryRedirect", "", "", "Argument[0]", "url-redirect", "manual"]
6+
- ["javax.ws.rs.core", "Response", True, "seeOther", "", "", "Argument[0]", "url-redirection", "manual"]
7+
- ["javax.ws.rs.core", "Response", True, "temporaryRedirect", "", "", "Argument[0]", "url-redirection", "manual"]
88
- ["javax.ws.rs.core", "ResponseBuilder", False, "header", "", "", "Argument[1]", "header-splitting", "manual"]
99
- addsTo:
1010
pack: codeql/java-all

java/ql/lib/ext/org.geogebra.web.full.main.model.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,4 +4,4 @@ extensions:
44
pack: codeql/java-all
55
extensible: sinkModel
66
data:
7-
- ["org.geogebra.web.full.main", "FileManager", True, "open", "(String,String)", "", "Argument[0]", "url-redirect", "ai-manual"]
7+
- ["org.geogebra.web.full.main", "FileManager", True, "open", "(String,String)", "", "Argument[0]", "url-redirection", "ai-manual"]

java/ql/lib/ext/org.kohsuke.stapler.model.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,5 +3,5 @@ extensions:
33
pack: codeql/java-all
44
extensible: sinkModel
55
data:
6-
- ["org.kohsuke.stapler", "HttpResponses", True, "redirectTo", "(String)", "", "Argument[0]", "url-redirect", "ai-manual"]
6+
- ["org.kohsuke.stapler", "HttpResponses", True, "redirectTo", "(String)", "", "Argument[0]", "url-redirection", "ai-manual"]
77
- ["org.kohsuke.stapler", "HttpResponses", True, "staticResource", "(URL)", "", "Argument[0]", "open-url", "ai-manual"]

java/ql/lib/semmle/code/java/dataflow/ExternalFlow.qll

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -276,7 +276,7 @@ module ModelValidation {
276276
[
277277
"open-url", "jndi-injection", "ldap", "sql-injection", "jdbc-url", "logging", "mvel",
278278
"xpath", "groovy", "xss", "ognl-injection", "intent-start", "pending-intent-sent",
279-
"url-redirect", "create-file", "read-file", "write-file", "set-hostname-verifier",
279+
"url-redirection", "create-file", "read-file", "write-file", "set-hostname-verifier",
280280
"header-splitting", "information-leak", "xslt", "jexl", "bean-validation", "ssti",
281281
"fragment-injection", "command-injection"
282282
] and

java/ql/lib/semmle/code/java/security/UrlRedirect.qll

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ abstract class UrlRedirectSink extends DataFlow::Node { }
1212

1313
/** A default sink represeting methods susceptible to URL redirection attacks. */
1414
private class DefaultUrlRedirectSink extends UrlRedirectSink {
15-
DefaultUrlRedirectSink() { sinkNode(this, "url-redirect") }
15+
DefaultUrlRedirectSink() { sinkNode(this, "url-redirection") }
1616
}
1717

1818
/** A Servlet URL redirection sink. */

0 commit comments

Comments
 (0)