From b305962c9abff2a66cf18a43d02a4d0cc0ae5d1d Mon Sep 17 00:00:00 2001 From: Ed Minnix Date: Fri, 28 Jul 2023 17:05:25 -0400 Subject: [PATCH] Use more appropriate description --- java/ql/src/Security/CWE/CWE-501/TrustBoundaryViolation.ql | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/java/ql/src/Security/CWE/CWE-501/TrustBoundaryViolation.ql b/java/ql/src/Security/CWE/CWE-501/TrustBoundaryViolation.ql index 93b433521e6..9bc90f49c1f 100644 --- a/java/ql/src/Security/CWE/CWE-501/TrustBoundaryViolation.ql +++ b/java/ql/src/Security/CWE/CWE-501/TrustBoundaryViolation.ql @@ -1,7 +1,7 @@ /** * @id java/trust-boundary-violation * @name Trust boundary violation - * @description A user-provided value is used to set a session attribute. + * @description Modifying the HTTP session attributes based on data from an untrusted source may violate a trust boundary. * @kind path-problem * @problem.severity error * @security-severity 8.8