diff --git a/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql b/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql index 682d83874333..1cb3be1f0c91 100644 --- a/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql +++ b/cpp/ql/src/Security/CWE/CWE-319/UseOfHttp.ql @@ -35,22 +35,25 @@ predicate privateHostNameFlowsToExpr(Expr e) { TaintTracking::localExprTaint(any(StringLiteral p | p.getValue() instanceof PrivateHostName), e) } -/** - * A string containing an HTTP URL not in a private domain. - */ -class HttpStringLiteral extends StringLiteral { - HttpStringLiteral() { +private class HttpStringLiteralCandidate extends StringLiteral { + HttpStringLiteralCandidate() { exists(string s | this.getValue() = s | s = "http" or exists(string tail | tail = s.regexpCapture("http://(.*)", 1) and not tail instanceof PrivateHostName ) - ) and - not privateHostNameFlowsToExpr(this.getParent*()) + ) } } +/** + * A string containing an HTTP URL not in a private domain. + */ +class HttpStringLiteral extends HttpStringLiteralCandidate { + HttpStringLiteral() { not privateHostNameFlowsToExpr(this.getParent*()) } +} + /** * Taint tracking configuration for HTTP connections. */