Skip to content

Commit e3af8b2

Browse files
committed
Move LdapInjectionLib to LdapInjectionQuery.qll
1 parent 1add692 commit e3af8b2

File tree

2 files changed

+4
-1
lines changed

2 files changed

+4
-1
lines changed

java/ql/src/Security/CWE/CWE-090/LdapInjectionLib.qll renamed to java/ql/lib/semmle/code/java/security/LdapInjectionQuery.qll

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,5 @@
1+
/** Provides a taint tracking configuration to reason about unvalidated user input that is used to construct LDAP queries. */
2+
13
import java
24
import semmle.code.java.dataflow.FlowSources
35
import semmle.code.java.security.LdapInjection
@@ -17,4 +19,5 @@ module LdapInjectionFlowConfig implements DataFlow::ConfigSig {
1719
}
1820
}
1921

22+
/** Tracks flow from remote sources to LDAP injection vulnerabilities. */
2023
module LdapInjectionFlow = TaintTracking::Global<LdapInjectionFlowConfig>;

java/ql/src/Security/CWE/CWE-090/LdapInjection.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@
1313

1414
import java
1515
import semmle.code.java.dataflow.FlowSources
16-
import LdapInjectionLib
16+
import semmle.code.java.security.LdapInjectionQuery
1717
import LdapInjectionFlow::PathGraph
1818

1919
from LdapInjectionFlow::PathNode source, LdapInjectionFlow::PathNode sink

0 commit comments

Comments
 (0)