We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 35e82dc commit bc19769Copy full SHA for bc19769
python/ql/src/Security/CWE-094/CodeInjection.ql
@@ -27,7 +27,7 @@ class CodeInjectionConfiguration extends TaintTracking::Configuration {
27
28
CodeInjectionConfiguration() { this = "Code injection configuration" }
29
30
- override predicate isSource(TaintTracking::Source source) { source.isSourceOf(any(UntrustedStringKind u)) }
+ override predicate isSource(TaintTracking::Source source) { source instanceof HttpRequestTaintSource }
31
32
override predicate isSink(TaintTracking::Sink sink) { sink instanceof StringEvaluationNode }
33
0 commit comments