Removing CWE-522 from this rule because CWE-522 maps to the "AUTH" SonarSource Security Category and this makes this RSPEC mapping to 2 SonarSource Security Category and we expect a given RSPEC to map to only one specific SonarSource Security Category. This is especially true for Security Hotspots the guided process introduced with \https://jira.sonarsource.com/browse/MMF-1868.