Hello, I would like to ask why the methods with parameters of the java.lang. class in the function summary are not recognized during analysis? For example: stringBuilder.append(132323).append(tainted);
ConnectionManager cm = new ConnectionManager();
cm.publish((stringBuilder.toString()));
The above code will not be missed, because 132323 is not a class starting with java.lang,
stringBuilder.append("132323").append(tainted);
ConnectionManager cm = new ConnectionManager();
cm.publish((stringBuilder.toString()));
The above code will be underreported because "132323" is java.lang.StringBuffer
Hello, I would like to ask why the methods with parameters of the java.lang. class in the function summary are not recognized during analysis? For example: stringBuilder.append(132323).append(tainted); ConnectionManager cm = new ConnectionManager(); cm.publish((stringBuilder.toString())); The above code will not be missed, because 132323 is not a class starting with java.lang, stringBuilder.append("132323").append(tainted); ConnectionManager cm = new ConnectionManager(); cm.publish((stringBuilder.toString())); The above code will be underreported because "132323" is java.lang.StringBuffer