=== on 17 Sep 2018, 18:55:00 Nicolas Harraudeau wrote: Note: JXPath is a little different as it targets Beans and other objects but it should be as vulnerable. === on 9 May 2019, 15:59:45 Nicolas Harraudeau wrote: This rule is deprecated for Java because it is handled by the taint analysis engine (RSPEC-2091). include::../comments-and-links.adoc[]