Skip to content

Commit bc19769

Browse files
committed
Python: make sure code injection query is using correct sources.
1 parent 35e82dc commit bc19769

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

python/ql/src/Security/CWE-094/CodeInjection.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ class CodeInjectionConfiguration extends TaintTracking::Configuration {
2727

2828
CodeInjectionConfiguration() { this = "Code injection configuration" }
2929

30-
override predicate isSource(TaintTracking::Source source) { source.isSourceOf(any(UntrustedStringKind u)) }
30+
override predicate isSource(TaintTracking::Source source) { source instanceof HttpRequestTaintSource }
3131

3232
override predicate isSink(TaintTracking::Sink sink) { sink instanceof StringEvaluationNode }
3333

0 commit comments

Comments
 (0)