Skip to content

Commit 0dd33b2

Browse files
Jami CogswellJami Cogswell
authored andcommitted
Java: remove version debugging from alert message
1 parent 7250265 commit 0dd33b2

File tree

2 files changed

+4
-10
lines changed

2 files changed

+4
-10
lines changed

java/ql/lib/semmle/code/java/security/SpringBootActuatorsConfigQuery.qll

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,9 +11,8 @@ private class SpringBootParent extends Parent {
1111
SpringBootParent() { this.getGroup().getValue() = "org.springframework.boot" }
1212
}
1313

14-
// TODO: private once done with version string debugging in alert msg.
1514
/** A `Pom` with a Spring Boot parent node. */
16-
class SpringBootPom extends Pom {
15+
private class SpringBootPom extends Pom {
1716
SpringBootPom() { this.getParentElement() instanceof SpringBootParent }
1817

1918
/** Holds if the Spring Boot Security module is used in the project. */

java/ql/src/Security/CWE/CWE-200/SpringBootActuatorsConfig/SpringBootActuatorsConfig.ql

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -15,11 +15,6 @@ import java
1515
import semmle.code.xml.MavenPom
1616
import semmle.code.java.security.SpringBootActuatorsConfigQuery
1717

18-
from SpringBootStarterActuatorDependency d, JavaPropertyOption jpOption, SpringBootPom pom
19-
where
20-
exposesSensitiveEndpoint(d, jpOption) and
21-
// TODO: remove pom; for debugging versions
22-
d = pom.getADependency()
23-
select d,
24-
"Insecure Spring Boot actuator $@ exposes sensitive endpoints (" +
25-
pom.getParentElement().getVersionString() + ").", jpOption, "configuration"
18+
from SpringBootStarterActuatorDependency d, JavaPropertyOption jpOption
19+
where exposesSensitiveEndpoint(d, jpOption)
20+
select d, "Insecure Spring Boot actuator $@ exposes sensitive endpoints.", jpOption, "configuration"

0 commit comments

Comments
 (0)