We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
java/insecure-bean-validation
1 parent 7b53649 commit e53a28cCopy full SHA for e53a28c
java/ql/lib/semmle/code/java/security/InsecureBeanValidationQuery.qll
@@ -60,6 +60,8 @@ module BeanValidationFlow = TaintTracking::Global<BeanValidationConfig>;
60
* A bean validation sink, such as method `buildConstraintViolationWithTemplate`
61
* declared on a subtype of `javax.validation.ConstraintValidatorContext`.
62
*/
63
-private class BeanValidationSink extends DataFlow::Node {
64
- BeanValidationSink() { sinkNode(this, "bean-validation") }
+abstract class BeanValidationSink extends DataFlow::Node { }
+
65
+private class ExternalBeanValidationSink extends BeanValidationSink {
66
+ ExternalBeanValidationSink() { sinkNode(this, "bean-validation") }
67
}
0 commit comments