All Downloads are FREE. Search and download functionalities are using the official Maven repository.

io.codemodder.codemods.harden-xmldecoder-stream.yaml Maven / Gradle / Ivy

The newest version!
rules:
  - id: harden-xmldecoder-stream
    patterns:
      - pattern: new XMLDecoder((InputStream $IS), ...)
      - pattern-not: new XMLDecoder(XMLDecoderSecurity.hardenStream($ARG), ...)
      - pattern-not-inside: |
          $RT $METHOD ($ARGS) {
            ...
            $IS = XMLDecoderSecurity.hardenStream(...);
            ...
          }
    message: Semgrep found a match
    languages:
      - java
    severity: WARNING




© 2015 - 2024 Weber Informatics LLC | Privacy Policy