Skip to content

Updated java SQL Injection rule to match hibernate Session related sinks

What does this MR do?

Updated java SQL Injection rule to match hibernate Session related sinks with String concatenation

What are the relevant issue numbers?

gitlab-org/gitlab#440960

Does this MR meet the acceptance criteria?

  • The test cases cover both positive and negative cases and are also annotated with appropriate semgrep annotations:
    • For positive cases: // ruleid: ...
    • For negative cases: // ok: ....
  • Following metadata fields exist for the rule(s) added/updated in this MR:
    • owasp with both 2017 and 2021 mappings.
    • category: "security"
    • cwe
    • shortDescription
    • security-severity
  • The message field is valid and contains a secure code example.
  • Applicable license is mentioned in the rule if embedded/taken from external source.
  • Relevant labels including workflow labels are appropriately selected.
Edited by Chathumina Vimukthi

Merge request reports