We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent c78f3f8 commit 1188e18Copy full SHA for 1188e18
java/ql/src/Security/CWE/CWE-113/ResponseSplitting.qll
@@ -32,6 +32,7 @@ class HeaderSplittingSink extends DataFlow::ExprNode {
32
33
class WhitelistedSource extends RemoteUserInput {
34
WhitelistedSource() {
35
- this.asExpr().(MethodAccess).getMethod() instanceof HttpServletRequestGetHeaderMethod
+ this.asExpr().(MethodAccess).getMethod() instanceof HttpServletRequestGetHeaderMethod or
36
+ this.asExpr().(MethodAccess).getMethod() instanceof CookieGetNameMethod
37
}
38
0 commit comments