Skip to content

Commit e027c8c

Browse files
dellaliberaesbena
andauthored
Update javascript/ql/src/experimental/Security/CWE-614/InsecureCookie.qll
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
1 parent a1f64e2 commit e027c8c

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

javascript/ql/src/experimental/Security/CWE-614/InsecureCookie.qll

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -124,9 +124,10 @@ module Cookie {
124124
*/
125125
class InsecureJsCookie extends Cookie {
126126
InsecureJsCookie() {
127-
this = DataFlow::globalVarRef("Cookie").getAMemberCall("set") or
128-
this = DataFlow::globalVarRef("Cookie").getAMemberCall("noConflict").getAMemberCall("set") or
129-
this = DataFlow::moduleMember("js-cookie", "set").getACall()
127+
this =
128+
[DataFlow::globalVarRef("Cookie"),
129+
DataFlow::globalVarRef("Cookie").getAMemberCall("noConflict"),
130+
DataFlow::moduleImport("js-cookie")].getAMemberCall("set")
130131
}
131132

132133
override string getKind() { result = "js-cookie" }

0 commit comments

Comments
 (0)