@@ -36,11 +36,19 @@ edges
36
36
| VelocitySSTI.java:59:17:59:44 | getParameter(...) : String | VelocitySSTI.java:62:42:62:45 | code : String |
37
37
| VelocitySSTI.java:62:25:62:46 | new StringReader(...) : StringReader | VelocitySSTI.java:63:25:63:30 | reader |
38
38
| VelocitySSTI.java:62:42:62:45 | code : String | VelocitySSTI.java:62:25:62:46 | new StringReader(...) : StringReader |
39
- | VelocitySSTI.java:69:17:69:44 | getParameter(...) : String | VelocitySSTI.java:77:21:77:27 | context |
40
- | VelocitySSTI.java:83:17:83:44 | getParameter(...) : String | VelocitySSTI.java:89:60:89:66 | context |
41
- | VelocitySSTI.java:95:17:95:44 | getParameter(...) : String | VelocitySSTI.java:102:11:102:17 | context |
42
- | VelocitySSTI.java:108:17:108:44 | getParameter(...) : String | VelocitySSTI.java:115:11:115:17 | context |
43
- | VelocitySSTI.java:120:17:120:44 | getParameter(...) : String | VelocitySSTI.java:123:37:123:40 | code |
39
+ | VelocitySSTI.java:69:17:69:44 | getParameter(...) : String | VelocitySSTI.java:72:23:72:26 | code : String |
40
+ | VelocitySSTI.java:72:3:72:9 | context [post update] : AbstractContext | VelocitySSTI.java:77:21:77:27 | context |
41
+ | VelocitySSTI.java:72:23:72:26 | code : String | VelocitySSTI.java:72:3:72:9 | context [post update] : AbstractContext |
42
+ | VelocitySSTI.java:83:17:83:44 | getParameter(...) : String | VelocitySSTI.java:86:23:86:26 | code : String |
43
+ | VelocitySSTI.java:86:3:86:9 | context [post update] : AbstractContext | VelocitySSTI.java:90:52:90:58 | context |
44
+ | VelocitySSTI.java:86:23:86:26 | code : String | VelocitySSTI.java:86:3:86:9 | context [post update] : AbstractContext |
45
+ | VelocitySSTI.java:96:17:96:44 | getParameter(...) : String | VelocitySSTI.java:99:23:99:26 | code : String |
46
+ | VelocitySSTI.java:99:3:99:9 | context [post update] : AbstractContext | VelocitySSTI.java:103:11:103:17 | context |
47
+ | VelocitySSTI.java:99:23:99:26 | code : String | VelocitySSTI.java:99:3:99:9 | context [post update] : AbstractContext |
48
+ | VelocitySSTI.java:109:17:109:44 | getParameter(...) : String | VelocitySSTI.java:112:23:112:26 | code : String |
49
+ | VelocitySSTI.java:112:3:112:9 | context [post update] : AbstractContext | VelocitySSTI.java:116:11:116:17 | context |
50
+ | VelocitySSTI.java:112:23:112:26 | code : String | VelocitySSTI.java:112:3:112:9 | context [post update] : AbstractContext |
51
+ | VelocitySSTI.java:121:17:121:44 | getParameter(...) : String | VelocitySSTI.java:124:37:124:40 | code |
44
52
nodes
45
53
| FreemarkerSSTI.java:23:17:23:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
46
54
| FreemarkerSSTI.java:24:19:24:40 | new StringReader(...) : StringReader | semmle.label | new StringReader(...) : StringReader |
@@ -99,15 +107,23 @@ nodes
99
107
| VelocitySSTI.java:62:42:62:45 | code : String | semmle.label | code : String |
100
108
| VelocitySSTI.java:63:25:63:30 | reader | semmle.label | reader |
101
109
| VelocitySSTI.java:69:17:69:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
110
+ | VelocitySSTI.java:72:3:72:9 | context [post update] : AbstractContext | semmle.label | context [post update] : AbstractContext |
111
+ | VelocitySSTI.java:72:23:72:26 | code : String | semmle.label | code : String |
102
112
| VelocitySSTI.java:77:21:77:27 | context | semmle.label | context |
103
113
| VelocitySSTI.java:83:17:83:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
104
- | VelocitySSTI.java:89:60:89:66 | context | semmle.label | context |
105
- | VelocitySSTI.java:95:17:95:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
106
- | VelocitySSTI.java:102:11:102:17 | context | semmle.label | context |
107
- | VelocitySSTI.java:108:17:108:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
108
- | VelocitySSTI.java:115:11:115:17 | context | semmle.label | context |
109
- | VelocitySSTI.java:120:17:120:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
110
- | VelocitySSTI.java:123:37:123:40 | code | semmle.label | code |
114
+ | VelocitySSTI.java:86:3:86:9 | context [post update] : AbstractContext | semmle.label | context [post update] : AbstractContext |
115
+ | VelocitySSTI.java:86:23:86:26 | code : String | semmle.label | code : String |
116
+ | VelocitySSTI.java:90:52:90:58 | context | semmle.label | context |
117
+ | VelocitySSTI.java:96:17:96:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
118
+ | VelocitySSTI.java:99:3:99:9 | context [post update] : AbstractContext | semmle.label | context [post update] : AbstractContext |
119
+ | VelocitySSTI.java:99:23:99:26 | code : String | semmle.label | code : String |
120
+ | VelocitySSTI.java:103:11:103:17 | context | semmle.label | context |
121
+ | VelocitySSTI.java:109:17:109:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
122
+ | VelocitySSTI.java:112:3:112:9 | context [post update] : AbstractContext | semmle.label | context [post update] : AbstractContext |
123
+ | VelocitySSTI.java:112:23:112:26 | code : String | semmle.label | code : String |
124
+ | VelocitySSTI.java:116:11:116:17 | context | semmle.label | context |
125
+ | VelocitySSTI.java:121:17:121:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
126
+ | VelocitySSTI.java:124:37:124:40 | code | semmle.label | code |
111
127
subpaths
112
128
#select
113
129
| FreemarkerSSTI.java:27:35:27:40 | reader | FreemarkerSSTI.java:23:17:23:44 | getParameter(...) : String | FreemarkerSSTI.java:27:35:27:40 | reader | Potential arbitrary code execution due to $@. | FreemarkerSSTI.java:23:17:23:44 | getParameter(...) | a template value loaded from a remote source. |
@@ -130,7 +146,7 @@ subpaths
130
146
| VelocitySSTI.java:53:45:53:50 | reader | VelocitySSTI.java:44:17:44:44 | getParameter(...) : String | VelocitySSTI.java:53:45:53:50 | reader | Potential arbitrary code execution due to $@. | VelocitySSTI.java:44:17:44:44 | getParameter(...) | a template value loaded from a remote source. |
131
147
| VelocitySSTI.java:63:25:63:30 | reader | VelocitySSTI.java:59:17:59:44 | getParameter(...) : String | VelocitySSTI.java:63:25:63:30 | reader | Potential arbitrary code execution due to $@. | VelocitySSTI.java:59:17:59:44 | getParameter(...) | a template value loaded from a remote source. |
132
148
| VelocitySSTI.java:77:21:77:27 | context | VelocitySSTI.java:69:17:69:44 | getParameter(...) : String | VelocitySSTI.java:77:21:77:27 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:69:17:69:44 | getParameter(...) | a template value loaded from a remote source. |
133
- | VelocitySSTI.java:89:60:89:66 | context | VelocitySSTI.java:83:17:83:44 | getParameter(...) : String | VelocitySSTI.java:89:60:89:66 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:83:17:83:44 | getParameter(...) | a template value loaded from a remote source. |
134
- | VelocitySSTI.java:102 :11:102 :17 | context | VelocitySSTI.java:95 :17:95 :44 | getParameter(...) : String | VelocitySSTI.java:102 :11:102 :17 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:95 :17:95 :44 | getParameter(...) | a template value loaded from a remote source. |
135
- | VelocitySSTI.java:115 :11:115 :17 | context | VelocitySSTI.java:108 :17:108 :44 | getParameter(...) : String | VelocitySSTI.java:115 :11:115 :17 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:108 :17:108 :44 | getParameter(...) | a template value loaded from a remote source. |
136
- | VelocitySSTI.java:123 :37:123 :40 | code | VelocitySSTI.java:120 :17:120 :44 | getParameter(...) : String | VelocitySSTI.java:123 :37:123 :40 | code | Potential arbitrary code execution due to $@. | VelocitySSTI.java:120 :17:120 :44 | getParameter(...) | a template value loaded from a remote source. |
149
+ | VelocitySSTI.java:90:52:90:58 | context | VelocitySSTI.java:83:17:83:44 | getParameter(...) : String | VelocitySSTI.java:90:52:90:58 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:83:17:83:44 | getParameter(...) | a template value loaded from a remote source. |
150
+ | VelocitySSTI.java:103 :11:103 :17 | context | VelocitySSTI.java:96 :17:96 :44 | getParameter(...) : String | VelocitySSTI.java:103 :11:103 :17 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:96 :17:96 :44 | getParameter(...) | a template value loaded from a remote source. |
151
+ | VelocitySSTI.java:116 :11:116 :17 | context | VelocitySSTI.java:109 :17:109 :44 | getParameter(...) : String | VelocitySSTI.java:116 :11:116 :17 | context | Potential arbitrary code execution due to $@. | VelocitySSTI.java:109 :17:109 :44 | getParameter(...) | a template value loaded from a remote source. |
152
+ | VelocitySSTI.java:124 :37:124 :40 | code | VelocitySSTI.java:121 :17:121 :44 | getParameter(...) : String | VelocitySSTI.java:124 :37:124 :40 | code | Potential arbitrary code execution due to $@. | VelocitySSTI.java:121 :17:121 :44 | getParameter(...) | a template value loaded from a remote source. |
0 commit comments