CodeQL library for Java
codeql/java-all 0.4.5 (changelog, source)

Predicate createJacksonJsonParserStep

Holds if fromNode to toNode is a dataflow step that creates a Jackson parser.

For example, a createParser(userString) call yields a JsonParser, which becomes dangerous if passed to an unsafely-configured ObjectMapper’s readValue method.

predicate createJacksonJsonParserStep(Node fromNode, Node toNode)