Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion java/ql/src/Security/CWE/CWE-089/SqlConcatenated.ql
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ import java
import semmle.code.java.security.SqlConcatenatedLib
import semmle.code.java.security.SqlInjectionQuery
import semmle.code.java.security.SqlConcatenatedQuery
private import semmle.code.java.dataflow.internal.ModelExclusions

from QueryInjectionSink query, Expr uncontrolled
where
Expand All @@ -27,6 +28,9 @@ where
UncontrolledStringBuilderSourceFlow::flow(DataFlow::exprNode(sbv.getToStringCall()), query)
)
) and
not queryIsTaintedBy(query, _, _)
not queryIsTaintedBy(query, _, _) and
// Exclude test files: SQL concatenation in tests is typically for test setup
// and does not represent a real security vulnerability.
not isInTestFile(query.asExpr().getFile())
select query, "Query built by concatenation with $@, which may be untrusted.", uncontrolled,
"this expression"
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
category: minorAnalysis
---

* The `java/concatenated-sql-query` query now excludes results in test files. SQL concatenation in test code (e.g., test setup and fixture creation) does not represent a real security vulnerability, and flagging it produces noise. MRVA validation on top-100 Java repositories showed this reduces false positives by approximately 73%.
Loading