CodeQL library for Java/Kotlin
codeql/java-all 0.9.2-dev (changelog, source)
Search

Module SensitiveResultReceiverQuery

Definitions for the sensitive result receiver query.

Import path

import semmle.code.java.security.SensitiveResultReceiverQuery

Imports

FlowSources

Provides classes representing various flow sources for taint tracking.

SensitiveActions

Sensitive data and methods for security.

TaintTracking

Provides classes for performing local (intra-procedural) and global (inter-procedural) taint-tracking analyses.

java

Provides all default Java QL imports.

Predicates

isSensitiveResultReceiver

Holds if there is a path from sensitive data at src to a result receiver at sink, and the receiver was obtained from an untrusted source recSrc.

sensitiveResultReceiver

DEPRECATED: Use isSensitiveResultReceiver instead.

Aliases

SensitiveResultReceiverFlow

Taint tracking flow for sensitive expressions flowing to untrusted result receivers.