Skip to content

Commit d7ad5a0

Browse files
committed
Python: List NoSQL injection sinks
1 parent 16e1a00 commit d7ad5a0

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

python/ql/src/meta/alerts/TaintSinks.ql

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -58,6 +58,10 @@ DataFlow::Node relevantTaintSink(string kind) {
5858
or
5959
kind = "RegexInjection" and result instanceof RegexInjection::Sink
6060
or
61+
kind = "NoSqlInjection (string sink)" and result instanceof NoSqlInjection::StringSink
62+
or
63+
kind = "NoSqlInjection (dict sink)" and result instanceof NoSqlInjection::DictSink
64+
or
6165
kind = "ServerSideRequestForgery" and result instanceof ServerSideRequestForgery::Sink
6266
or
6367
kind = "SqlInjection" and result instanceof SqlInjection::Sink

0 commit comments

Comments
 (0)