Skip to content

Commit 2978af3

Browse files
committed
Java: Add RestTemplate as flow source.
1 parent f2edc53 commit 2978af3

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

java/ql/src/semmle/code/java/dataflow/FlowSources.qll

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,7 @@ import semmle.code.java.frameworks.JaxWS
1818
import semmle.code.java.frameworks.android.Intent
1919
import semmle.code.java.frameworks.spring.SpringWeb
2020
import semmle.code.java.frameworks.spring.SpringController
21+
import semmle.code.java.frameworks.spring.SpringWebClient
2122
import semmle.code.java.frameworks.Guice
2223
import semmle.code.java.frameworks.struts.StrutsActions
2324
import semmle.code.java.frameworks.Thrift
@@ -228,6 +229,7 @@ private class RemoteTaintedMethod extends Method {
228229
this.hasName("getParameterValues")
229230
// TODO consider getRemoteUser
230231
) or
232+
this instanceof SpringRestTemplateResponseEntityMethod or
231233
this instanceof ServletRequestGetBodyMethod or
232234
this instanceof CookieGetValueMethod or
233235
this instanceof CookieGetNameMethod or

0 commit comments

Comments
 (0)