Skip to content

Commit 822bfcd

Browse files
committed
Nit: fix qhelp
1 parent 5e912cb commit 822bfcd

File tree

2 files changed

+7
-7
lines changed

2 files changed

+7
-7
lines changed

java/ql/src/experimental/CWE-094/ScriptEngine.qhelp

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,16 +4,16 @@
44
<qhelp>
55

66
<overview>
7-
<p> The ScriptEngine api is available since the release of Java 6.
8-
It allows application to interact with script written in language such as JavaScript.</p>
7+
<p>The ScriptEngine API has been available since the release of Java 6.
8+
It allows applications to interact with scripts written in languages such as JavaScript.</p>
99
</overview>
1010

1111
<recommendation>
12-
Use "Cloudbees Rhino Sandbox" or sandboxing with SecurityManager or use <a href="https://www.graalvm.org/">graalvm</a> instead
12+
<p>Use "Cloudbees Rhino Sandbox" or sandboxing with SecurityManager or use <a href="https://www.graalvm.org/">graalvm</a> instead.</p>
1313
</recommendation>
1414

1515
<example>
16-
The following code could executes random JavaScript code
16+
<p>The following code could execute random JavaScript code</p>
1717
<sample src="ScriptEngine.java" />
1818
</example>
1919

java/ql/src/experimental/CWE-094/ScriptEngine.ql

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
/**
2-
* @name Script engine eval
3-
* @description Malicious javascript code could caused arbitrary command execution on OS level
2+
* @name ScriptEngine evaluation
3+
* @description Malicious Javascript code could cause arbitrary command execution at the OS level
44
* @kind path-problem
55
* @problem.severity error
66
* @precision high
@@ -47,5 +47,5 @@ class ScriptEngineConfiguration extends TaintTracking::Configuration {
4747

4848
from DataFlow::PathNode source, DataFlow::PathNode sink, ScriptEngineConfiguration conf
4949
where conf.hasFlowPath(source, sink)
50-
select sink.getNode().(ScriptEngineSink).getMethodAccess(), source, sink, "Script engine eval $@.",
50+
select sink.getNode().(ScriptEngineSink).getMethodAccess(), source, sink, "ScriptEngine eval $@.",
5151
source.getNode(), "user input"

0 commit comments

Comments
 (0)