Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion java/ql/lib/semmle/code/java/security/ZipSlipQuery.qll
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ import semmle.code.java.security.PathSanitizer
private import semmle.code.java.dataflow.ExternalFlow
private import semmle.code.java.dataflow.FlowSources
private import semmle.code.java.security.PathCreation
private import semmle.code.java.security.Sanitizers

/**
* A method that returns the name of an archive entry.
Expand Down Expand Up @@ -39,7 +40,10 @@ module ZipSlipConfig implements DataFlow::ConfigSig {

predicate isSink(DataFlow::Node sink) { sink instanceof FileCreationSink }

predicate isBarrier(DataFlow::Node node) { node instanceof PathInjectionSanitizer }
predicate isBarrier(DataFlow::Node node) {
node instanceof SimpleTypeSanitizer or
node instanceof PathInjectionSanitizer
}
}

/** Tracks flow from archive entries to file creation. */
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
---
category: minorAnalysis
---
* The sanitizer of the query `java/zipslip` has been improved to include nodes that are safe due to having certain safe types. This reduces false positives.