More context on the steps reported on taint vulnerability issues

Hello,

We updated our security engine so that it reports easier-to-read data flows so you can make a decision with more context and fix faster the reported taint vulnerabilities.

Previously the data flow was very generic and was only talking about “tainted value is propagated” which is not the best to understand what’s going on:

image

Now it looks like this on SonarCloud and SonarQube 9.6+:

image

Alex

6 Likes