File tree Expand file tree Collapse file tree 2 files changed +2
-2
lines changed
semmle/python/security/injection Expand file tree Collapse file tree 2 files changed +2
-2
lines changed Original file line number Diff line number Diff line change @@ -28,7 +28,7 @@ class UnsafeDeserializationConfiguration extends TaintTracking::Configuration {
2828
2929 UnsafeDeserializationConfiguration ( ) { this = "Unsafe deserialization configuration" }
3030
31- override predicate isSource ( TaintTracking:: Source source ) { source . isSourceOf ( any ( UntrustedStringKind u ) ) }
31+ override predicate isSource ( TaintTracking:: Source source ) { source instanceof HttpRequestTaintSource }
3232
3333 override predicate isSink ( TaintTracking:: Sink sink ) { sink instanceof DeserializationSink }
3434
Original file line number Diff line number Diff line change @@ -25,7 +25,7 @@ private FunctionObject pickleLoads() {
2525}
2626
2727/** `pickle.loads(untrusted)` vulnerability. */
28- class UnpicklingNode extends TaintSink {
28+ class UnpicklingNode extends DeserializationSink {
2929
3030 override string toString ( ) { result = "unpickling untrusted data" }
3131
You can’t perform that action at this time.
0 commit comments