Skip to content

Commit 11665be

Browse files
committed
Java: Allow taint-read-steps for array sources.
1 parent 402d58b commit 11665be

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

java/ql/lib/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -655,6 +655,8 @@ private SrcRefType entrypointType() {
655655
)
656656
or
657657
result = entrypointType().getAField().getType().(RefType).getSourceDeclaration()
658+
or
659+
result = entrypointType().(Array).getElementType().(RefType).getSourceDeclaration()
658660
}
659661

660662
private predicate entrypointFieldStep(DataFlow::Node src, DataFlow::Node sink) {

0 commit comments

Comments
 (0)