Skip to content

Commit dfcb38d

Browse files
committed
Java: Promote models for CWE-078.
1 parent 56a9783 commit dfcb38d

File tree

2 files changed

+2
-6
lines changed

2 files changed

+2
-6
lines changed
Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
extensions:
22
- addsTo:
33
pack: codeql/java-all
4-
extensible: experimentalSinkModel
4+
extensible: sinkModel
55
data:
6-
- ["com.jcraft.jsch", "ChannelExec", True, "setCommand", "", "", "Argument[0]", "command-injection", "manual", "jsch-os-injection"]
6+
- ["com.jcraft.jsch", "ChannelExec", True, "setCommand", "", "", "Argument[0]", "command-injection", "manual"] #jsch-os-injection

java/src/security/CWE-078/ExecTainted.ql

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,10 +16,6 @@ import semmle.code.java.security.CommandLineQuery
1616
import InputToArgumentToExecFlow::PathGraph
1717
private import semmle.code.java.dataflow.ExternalFlow
1818

19-
private class ActivateModels extends ActiveExperimentalModels {
20-
ActivateModels() { this = "jsch-os-injection" }
21-
}
22-
2319
// This is a clone of query `java/command-line-injection` that also includes experimental sinks.
2420
from
2521
InputToArgumentToExecFlow::PathNode source, InputToArgumentToExecFlow::PathNode sink, Expr execArg

0 commit comments

Comments
 (0)