Skip to content

Commit 60c536d

Browse files
committed
Java: Add RestTemplate as flow source.
1 parent b81ece3 commit 60c536d

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

java/ql/src/semmle/code/java/dataflow/FlowSources.qll

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,7 @@ import semmle.code.java.frameworks.JaxWS
1818
import semmle.code.java.frameworks.android.Intent
1919
import semmle.code.java.frameworks.spring.SpringWeb
2020
import semmle.code.java.frameworks.spring.SpringController
21+
import semmle.code.java.frameworks.spring.SpringWebClient
2122
import semmle.code.java.frameworks.Guice
2223
import semmle.code.java.frameworks.struts.StrutsActions
2324
import semmle.code.java.frameworks.Thrift
@@ -210,6 +211,7 @@ private class RemoteTaintedMethod extends Method {
210211
this.hasName("getParameterValues")
211212
// TODO consider getRemoteUser
212213
) or
214+
this instanceof SpringRestTemplateResponseEntityMethod or
213215
this instanceof ServletRequestGetBodyMethod or
214216
this instanceof CookieGetValueMethod or
215217
this instanceof CookieGetNameMethod or

0 commit comments

Comments
 (0)