Module NosqlInjectionConfig
A taint-tracking configuration for reasoning about SQL-injection vulnerabilities.
Import path
import semmle.javascript.security.dataflow.NosqlInjectionQueryImports
| CommonFlowState | Contains a class with flow states that are used by multiple queries. |
Predicates
| isAdditionalFlowStep | Holds if data may flow from |
| isBarrier | Holds if data flow through |
| isSink | Holds if |
| isSource | Holds if |
| observeDiffInformedIncrementalMode | Holds if sources and sinks should be filtered to only include those that may lead to a flow path with either a source or a sink in the location range given by |