Skip to content

Log Forging with types different than string. #10454

Discussion options

You must be logged in to vote

Greetings, many thanks for raising this with us. It does indeed sound like there is an opportunity to reduce false positives on this query by enhancing our analysis to consider the types of variables flowing into the logs. I'll raise this with our C# analysis team so they can consider whether to prioritize making this change.

Replies: 2 comments 3 replies

Comment options

You must be logged in to vote
1 reply
@WSkwieVolue
Comment options

Answer selected by WSkwieVolue
Comment options

You must be logged in to vote
2 replies
@WSkwieVolue
Comment options

@michaelnebel
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants