From 32f146fbcad853552969cc8ed07ac4f072ab3238 Mon Sep 17 00:00:00 2001 From: yo-h <55373593+yo-h@users.noreply.github.com> Date: Thu, 12 Dec 2019 14:31:06 -0500 Subject: [PATCH] Java: add change note for `java/netty-http-response-splitting` --- change-notes/1.23/analysis-java.md | 1 + 1 file changed, 1 insertion(+) diff --git a/change-notes/1.23/analysis-java.md b/change-notes/1.23/analysis-java.md index ad1f22489129..e6355407dbd1 100644 --- a/change-notes/1.23/analysis-java.md +++ b/change-notes/1.23/analysis-java.md @@ -7,6 +7,7 @@ The following changes in version 1.23 affect Java analysis in all applications. | **Query** | **Tags** | **Purpose** | |-----------------------------|-----------|--------------------------------------------------------------------| | Continue statement that does not continue (`java/continue-in-false-loop`) | correctness | Finds `continue` statements in `do { ... } while (false)` loops. Results are shown on LGTM by default. | +| Disabled Netty HTTP header validation (`java/netty-http-response-splitting`) | security, external/cwe/cwe-113 | Finds response-splitting vulnerabilities due to Netty HTTP header validation being disabled. Results are shown on LGTM by default. | ## Changes to existing queries