[Java] Dataflow through object
未關閉
question
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
Hello,
I am getting some false positives with some of my queries, which are usually centered around a source node flowing into an object and then other data from that object flowing into a sink node.
Here is a simple example,
```
env.put(Context.SECURITY_CREDENTIALS, password);
LOG.error("connection error [{}], failover connection to [{}]", env.get(Context.PROVIDER_URL), this.ldapURI.toString());
```
In this case, `password` is a source variable. While `LOG.error` is a sink. However, by having it flow into `env`, it now marks any use of the object as a detection eventough this case has nothing to do with `password`. Is there any way to reduce cases like this?
Thank you
貢獻指南
評估
這個 Issue 還沒有評估資料。