|
|
|
|
@@ -1,36 +1,45 @@
|
|
|
|
|
edges
|
|
|
|
|
| PlistUnsafeDeserialization.rb:5:30:5:35 | call to params | PlistUnsafeDeserialization.rb:5:30:5:49 | ...[...] |
|
|
|
|
|
| PlistUnsafeDeserialization.rb:6:30:6:35 | call to params | PlistUnsafeDeserialization.rb:6:30:6:49 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:10:5:10:19 | serialized_data | UnsafeDeserialization.rb:11:27:11:41 | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:10:23:10:50 | call to decode64 | UnsafeDeserialization.rb:10:5:10:19 | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:10:39:10:44 | call to params | UnsafeDeserialization.rb:10:39:10:50 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:10:39:10:50 | ...[...] | UnsafeDeserialization.rb:10:23:10:50 | call to decode64 |
|
|
|
|
|
| UnsafeDeserialization.rb:16:5:16:19 | serialized_data | UnsafeDeserialization.rb:17:30:17:44 | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:16:23:16:50 | call to decode64 | UnsafeDeserialization.rb:16:5:16:19 | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:16:39:16:44 | call to params | UnsafeDeserialization.rb:16:39:16:50 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:16:39:16:50 | ...[...] | UnsafeDeserialization.rb:16:23:16:50 | call to decode64 |
|
|
|
|
|
| UnsafeDeserialization.rb:22:5:22:13 | json_data | UnsafeDeserialization.rb:23:24:23:32 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:22:17:22:22 | call to params | UnsafeDeserialization.rb:22:17:22:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:22:17:22:28 | ...[...] | UnsafeDeserialization.rb:22:5:22:13 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:28:5:28:13 | json_data | UnsafeDeserialization.rb:29:27:29:35 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:28:17:28:22 | call to params | UnsafeDeserialization.rb:28:17:28:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:28:17:28:28 | ...[...] | UnsafeDeserialization.rb:28:5:28:13 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:40:5:40:13 | yaml_data | UnsafeDeserialization.rb:41:24:41:32 | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:40:17:40:22 | call to params | UnsafeDeserialization.rb:40:17:40:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:40:17:40:28 | ...[...] | UnsafeDeserialization.rb:40:5:40:13 | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:52:5:52:13 | json_data | UnsafeDeserialization.rb:53:22:53:30 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:52:5:52:13 | json_data | UnsafeDeserialization.rb:54:22:54:30 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:52:17:52:22 | call to params | UnsafeDeserialization.rb:52:17:52:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:52:17:52:28 | ...[...] | UnsafeDeserialization.rb:52:5:52:13 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:59:5:59:13 | json_data | UnsafeDeserialization.rb:69:23:69:31 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:59:17:59:22 | call to params | UnsafeDeserialization.rb:59:17:59:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:59:17:59:28 | ...[...] | UnsafeDeserialization.rb:59:5:59:13 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:81:5:81:7 | xml | UnsafeDeserialization.rb:82:34:82:36 | xml |
|
|
|
|
|
| UnsafeDeserialization.rb:81:11:81:16 | call to params | UnsafeDeserialization.rb:81:11:81:22 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:81:11:81:22 | ...[...] | UnsafeDeserialization.rb:81:5:81:7 | xml |
|
|
|
|
|
| UnsafeDeserialization.rb:87:5:87:13 | yaml_data | UnsafeDeserialization.rb:88:25:88:33 | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:87:17:87:22 | call to params | UnsafeDeserialization.rb:87:17:87:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:87:17:87:28 | ...[...] | UnsafeDeserialization.rb:87:5:87:13 | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:11:5:11:19 | serialized_data | UnsafeDeserialization.rb:12:27:12:41 | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:11:23:11:50 | call to decode64 | UnsafeDeserialization.rb:11:5:11:19 | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:11:39:11:44 | call to params | UnsafeDeserialization.rb:11:39:11:50 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:11:39:11:50 | ...[...] | UnsafeDeserialization.rb:11:23:11:50 | call to decode64 |
|
|
|
|
|
| UnsafeDeserialization.rb:17:5:17:19 | serialized_data | UnsafeDeserialization.rb:18:30:18:44 | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:17:23:17:50 | call to decode64 | UnsafeDeserialization.rb:17:5:17:19 | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:17:39:17:44 | call to params | UnsafeDeserialization.rb:17:39:17:50 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:17:39:17:50 | ...[...] | UnsafeDeserialization.rb:17:23:17:50 | call to decode64 |
|
|
|
|
|
| UnsafeDeserialization.rb:23:5:23:13 | json_data | UnsafeDeserialization.rb:24:24:24:32 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:23:17:23:22 | call to params | UnsafeDeserialization.rb:23:17:23:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:23:17:23:28 | ...[...] | UnsafeDeserialization.rb:23:5:23:13 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:29:5:29:13 | json_data | UnsafeDeserialization.rb:30:27:30:35 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:29:17:29:22 | call to params | UnsafeDeserialization.rb:29:17:29:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:29:17:29:28 | ...[...] | UnsafeDeserialization.rb:29:5:29:13 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:41:5:41:13 | yaml_data | UnsafeDeserialization.rb:42:24:42:32 | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:41:17:41:22 | call to params | UnsafeDeserialization.rb:41:17:41:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:41:17:41:28 | ...[...] | UnsafeDeserialization.rb:41:5:41:13 | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:53:5:53:13 | json_data | UnsafeDeserialization.rb:54:22:54:30 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:53:5:53:13 | json_data | UnsafeDeserialization.rb:55:22:55:30 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:53:17:53:22 | call to params | UnsafeDeserialization.rb:53:17:53:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:53:17:53:28 | ...[...] | UnsafeDeserialization.rb:53:5:53:13 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:60:5:60:13 | json_data | UnsafeDeserialization.rb:70:23:70:31 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:60:17:60:22 | call to params | UnsafeDeserialization.rb:60:17:60:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:60:17:60:28 | ...[...] | UnsafeDeserialization.rb:60:5:60:13 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:81:4:81:12 | json_data | UnsafeDeserialization.rb:82:28:82:36 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:81:16:81:21 | call to params | UnsafeDeserialization.rb:81:16:81:27 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:81:16:81:27 | ...[...] | UnsafeDeserialization.rb:81:4:81:12 | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:87:4:87:11 | xml_data | UnsafeDeserialization.rb:88:26:88:33 | xml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:87:15:87:20 | call to params | UnsafeDeserialization.rb:87:15:87:26 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:87:15:87:26 | ...[...] | UnsafeDeserialization.rb:87:4:87:11 | xml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:93:5:93:12 | xml_data | UnsafeDeserialization.rb:94:22:94:29 | xml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:93:16:93:21 | call to params | UnsafeDeserialization.rb:93:16:93:27 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:93:16:93:27 | ...[...] | UnsafeDeserialization.rb:93:5:93:12 | xml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:109:5:109:7 | xml | UnsafeDeserialization.rb:110:34:110:36 | xml |
|
|
|
|
|
| UnsafeDeserialization.rb:109:11:109:16 | call to params | UnsafeDeserialization.rb:109:11:109:22 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:109:11:109:22 | ...[...] | UnsafeDeserialization.rb:109:5:109:7 | xml |
|
|
|
|
|
| UnsafeDeserialization.rb:115:5:115:13 | yaml_data | UnsafeDeserialization.rb:116:25:116:33 | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:115:17:115:22 | call to params | UnsafeDeserialization.rb:115:17:115:28 | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:115:17:115:28 | ...[...] | UnsafeDeserialization.rb:115:5:115:13 | yaml_data |
|
|
|
|
|
| YAMLUnsafeDeserialization.rb:5:16:5:21 | call to params | YAMLUnsafeDeserialization.rb:5:16:5:35 | ...[...] |
|
|
|
|
|
| YAMLUnsafeDeserialization.rb:11:23:11:28 | call to params | YAMLUnsafeDeserialization.rb:11:23:11:42 | ...[...] |
|
|
|
|
|
| YAMLUnsafeDeserialization.rb:12:28:12:33 | call to params | YAMLUnsafeDeserialization.rb:12:28:12:45 | ...[...] |
|
|
|
|
|
@@ -46,50 +55,62 @@ nodes
|
|
|
|
|
| PlistUnsafeDeserialization.rb:5:30:5:49 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| PlistUnsafeDeserialization.rb:6:30:6:35 | call to params | semmle.label | call to params |
|
|
|
|
|
| PlistUnsafeDeserialization.rb:6:30:6:49 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:10:5:10:19 | serialized_data | semmle.label | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:10:23:10:50 | call to decode64 | semmle.label | call to decode64 |
|
|
|
|
|
| UnsafeDeserialization.rb:10:39:10:44 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:10:39:10:50 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:11:27:11:41 | serialized_data | semmle.label | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:16:5:16:19 | serialized_data | semmle.label | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:16:23:16:50 | call to decode64 | semmle.label | call to decode64 |
|
|
|
|
|
| UnsafeDeserialization.rb:16:39:16:44 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:16:39:16:50 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:17:30:17:44 | serialized_data | semmle.label | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:22:5:22:13 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:22:17:22:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:22:17:22:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:23:24:23:32 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:28:5:28:13 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:28:17:28:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:28:17:28:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:29:27:29:35 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:40:5:40:13 | yaml_data | semmle.label | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:40:17:40:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:40:17:40:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:41:24:41:32 | yaml_data | semmle.label | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:52:5:52:13 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:52:17:52:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:52:17:52:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:53:22:53:30 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:11:5:11:19 | serialized_data | semmle.label | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:11:23:11:50 | call to decode64 | semmle.label | call to decode64 |
|
|
|
|
|
| UnsafeDeserialization.rb:11:39:11:44 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:11:39:11:50 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:12:27:12:41 | serialized_data | semmle.label | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:17:5:17:19 | serialized_data | semmle.label | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:17:23:17:50 | call to decode64 | semmle.label | call to decode64 |
|
|
|
|
|
| UnsafeDeserialization.rb:17:39:17:44 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:17:39:17:50 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:18:30:18:44 | serialized_data | semmle.label | serialized_data |
|
|
|
|
|
| UnsafeDeserialization.rb:23:5:23:13 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:23:17:23:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:23:17:23:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:24:24:24:32 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:29:5:29:13 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:29:17:29:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:29:17:29:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:30:27:30:35 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:41:5:41:13 | yaml_data | semmle.label | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:41:17:41:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:41:17:41:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:42:24:42:32 | yaml_data | semmle.label | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:53:5:53:13 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:53:17:53:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:53:17:53:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:54:22:54:30 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:59:5:59:13 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:59:17:59:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:59:17:59:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:69:23:69:31 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:81:5:81:7 | xml | semmle.label | xml |
|
|
|
|
|
| UnsafeDeserialization.rb:81:11:81:16 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:81:11:81:22 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:82:34:82:36 | xml | semmle.label | xml |
|
|
|
|
|
| UnsafeDeserialization.rb:87:5:87:13 | yaml_data | semmle.label | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:87:17:87:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:87:17:87:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:88:25:88:33 | yaml_data | semmle.label | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:92:24:92:34 | call to read | semmle.label | call to read |
|
|
|
|
|
| UnsafeDeserialization.rb:95:24:95:33 | call to gets | semmle.label | call to gets |
|
|
|
|
|
| UnsafeDeserialization.rb:98:24:98:32 | call to read | semmle.label | call to read |
|
|
|
|
|
| UnsafeDeserialization.rb:101:24:101:27 | call to gets | semmle.label | call to gets |
|
|
|
|
|
| UnsafeDeserialization.rb:104:24:104:32 | call to readlines | semmle.label | call to readlines |
|
|
|
|
|
| UnsafeDeserialization.rb:55:22:55:30 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:60:5:60:13 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:60:17:60:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:60:17:60:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:70:23:70:31 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:81:4:81:12 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:81:16:81:21 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:81:16:81:27 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:82:28:82:36 | json_data | semmle.label | json_data |
|
|
|
|
|
| UnsafeDeserialization.rb:87:4:87:11 | xml_data | semmle.label | xml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:87:15:87:20 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:87:15:87:26 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:88:26:88:33 | xml_data | semmle.label | xml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:93:5:93:12 | xml_data | semmle.label | xml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:93:16:93:21 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:93:16:93:27 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:94:22:94:29 | xml_data | semmle.label | xml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:109:5:109:7 | xml | semmle.label | xml |
|
|
|
|
|
| UnsafeDeserialization.rb:109:11:109:16 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:109:11:109:22 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:110:34:110:36 | xml | semmle.label | xml |
|
|
|
|
|
| UnsafeDeserialization.rb:115:5:115:13 | yaml_data | semmle.label | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:115:17:115:22 | call to params | semmle.label | call to params |
|
|
|
|
|
| UnsafeDeserialization.rb:115:17:115:28 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| UnsafeDeserialization.rb:116:25:116:33 | yaml_data | semmle.label | yaml_data |
|
|
|
|
|
| UnsafeDeserialization.rb:120:24:120:34 | call to read | semmle.label | call to read |
|
|
|
|
|
| UnsafeDeserialization.rb:123:24:123:33 | call to gets | semmle.label | call to gets |
|
|
|
|
|
| UnsafeDeserialization.rb:126:24:126:32 | call to read | semmle.label | call to read |
|
|
|
|
|
| UnsafeDeserialization.rb:129:24:129:27 | call to gets | semmle.label | call to gets |
|
|
|
|
|
| UnsafeDeserialization.rb:132:24:132:32 | call to readlines | semmle.label | call to readlines |
|
|
|
|
|
| YAMLUnsafeDeserialization.rb:5:16:5:21 | call to params | semmle.label | call to params |
|
|
|
|
|
| YAMLUnsafeDeserialization.rb:5:16:5:35 | ...[...] | semmle.label | ...[...] |
|
|
|
|
|
| YAMLUnsafeDeserialization.rb:11:23:11:28 | call to params | semmle.label | call to params |
|
|
|
|
|
@@ -111,21 +132,24 @@ subpaths
|
|
|
|
|
#select
|
|
|
|
|
| PlistUnsafeDeserialization.rb:5:30:5:49 | ...[...] | PlistUnsafeDeserialization.rb:5:30:5:35 | call to params | PlistUnsafeDeserialization.rb:5:30:5:49 | ...[...] | Unsafe deserialization depends on a $@. | PlistUnsafeDeserialization.rb:5:30:5:35 | call to params | user-provided value |
|
|
|
|
|
| PlistUnsafeDeserialization.rb:6:30:6:49 | ...[...] | PlistUnsafeDeserialization.rb:6:30:6:35 | call to params | PlistUnsafeDeserialization.rb:6:30:6:49 | ...[...] | Unsafe deserialization depends on a $@. | PlistUnsafeDeserialization.rb:6:30:6:35 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:11:27:11:41 | serialized_data | UnsafeDeserialization.rb:10:39:10:44 | call to params | UnsafeDeserialization.rb:11:27:11:41 | serialized_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:10:39:10:44 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:17:30:17:44 | serialized_data | UnsafeDeserialization.rb:16:39:16:44 | call to params | UnsafeDeserialization.rb:17:30:17:44 | serialized_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:16:39:16:44 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:23:24:23:32 | json_data | UnsafeDeserialization.rb:22:17:22:22 | call to params | UnsafeDeserialization.rb:23:24:23:32 | json_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:22:17:22:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:29:27:29:35 | json_data | UnsafeDeserialization.rb:28:17:28:22 | call to params | UnsafeDeserialization.rb:29:27:29:35 | json_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:28:17:28:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:41:24:41:32 | yaml_data | UnsafeDeserialization.rb:40:17:40:22 | call to params | UnsafeDeserialization.rb:41:24:41:32 | yaml_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:40:17:40:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:53:22:53:30 | json_data | UnsafeDeserialization.rb:52:17:52:22 | call to params | UnsafeDeserialization.rb:53:22:53:30 | json_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:52:17:52:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:54:22:54:30 | json_data | UnsafeDeserialization.rb:52:17:52:22 | call to params | UnsafeDeserialization.rb:54:22:54:30 | json_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:52:17:52:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:69:23:69:31 | json_data | UnsafeDeserialization.rb:59:17:59:22 | call to params | UnsafeDeserialization.rb:69:23:69:31 | json_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:59:17:59:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:82:34:82:36 | xml | UnsafeDeserialization.rb:81:11:81:16 | call to params | UnsafeDeserialization.rb:82:34:82:36 | xml | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:81:11:81:16 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:88:25:88:33 | yaml_data | UnsafeDeserialization.rb:87:17:87:22 | call to params | UnsafeDeserialization.rb:88:25:88:33 | yaml_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:87:17:87:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:92:24:92:34 | call to read | UnsafeDeserialization.rb:92:24:92:34 | call to read | UnsafeDeserialization.rb:92:24:92:34 | call to read | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:92:24:92:34 | call to read | value from stdin |
|
|
|
|
|
| UnsafeDeserialization.rb:95:24:95:33 | call to gets | UnsafeDeserialization.rb:95:24:95:33 | call to gets | UnsafeDeserialization.rb:95:24:95:33 | call to gets | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:95:24:95:33 | call to gets | value from stdin |
|
|
|
|
|
| UnsafeDeserialization.rb:98:24:98:32 | call to read | UnsafeDeserialization.rb:98:24:98:32 | call to read | UnsafeDeserialization.rb:98:24:98:32 | call to read | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:98:24:98:32 | call to read | value from stdin |
|
|
|
|
|
| UnsafeDeserialization.rb:101:24:101:27 | call to gets | UnsafeDeserialization.rb:101:24:101:27 | call to gets | UnsafeDeserialization.rb:101:24:101:27 | call to gets | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:101:24:101:27 | call to gets | value from stdin |
|
|
|
|
|
| UnsafeDeserialization.rb:104:24:104:32 | call to readlines | UnsafeDeserialization.rb:104:24:104:32 | call to readlines | UnsafeDeserialization.rb:104:24:104:32 | call to readlines | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:104:24:104:32 | call to readlines | value from stdin |
|
|
|
|
|
| UnsafeDeserialization.rb:12:27:12:41 | serialized_data | UnsafeDeserialization.rb:11:39:11:44 | call to params | UnsafeDeserialization.rb:12:27:12:41 | serialized_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:11:39:11:44 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:18:30:18:44 | serialized_data | UnsafeDeserialization.rb:17:39:17:44 | call to params | UnsafeDeserialization.rb:18:30:18:44 | serialized_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:17:39:17:44 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:24:24:24:32 | json_data | UnsafeDeserialization.rb:23:17:23:22 | call to params | UnsafeDeserialization.rb:24:24:24:32 | json_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:23:17:23:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:30:27:30:35 | json_data | UnsafeDeserialization.rb:29:17:29:22 | call to params | UnsafeDeserialization.rb:30:27:30:35 | json_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:29:17:29:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:42:24:42:32 | yaml_data | UnsafeDeserialization.rb:41:17:41:22 | call to params | UnsafeDeserialization.rb:42:24:42:32 | yaml_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:41:17:41:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:54:22:54:30 | json_data | UnsafeDeserialization.rb:53:17:53:22 | call to params | UnsafeDeserialization.rb:54:22:54:30 | json_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:53:17:53:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:55:22:55:30 | json_data | UnsafeDeserialization.rb:53:17:53:22 | call to params | UnsafeDeserialization.rb:55:22:55:30 | json_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:53:17:53:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:70:23:70:31 | json_data | UnsafeDeserialization.rb:60:17:60:22 | call to params | UnsafeDeserialization.rb:70:23:70:31 | json_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:60:17:60:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:82:28:82:36 | json_data | UnsafeDeserialization.rb:81:16:81:21 | call to params | UnsafeDeserialization.rb:82:28:82:36 | json_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:81:16:81:21 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:88:26:88:33 | xml_data | UnsafeDeserialization.rb:87:15:87:20 | call to params | UnsafeDeserialization.rb:88:26:88:33 | xml_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:87:15:87:20 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:94:22:94:29 | xml_data | UnsafeDeserialization.rb:93:16:93:21 | call to params | UnsafeDeserialization.rb:94:22:94:29 | xml_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:93:16:93:21 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:110:34:110:36 | xml | UnsafeDeserialization.rb:109:11:109:16 | call to params | UnsafeDeserialization.rb:110:34:110:36 | xml | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:109:11:109:16 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:116:25:116:33 | yaml_data | UnsafeDeserialization.rb:115:17:115:22 | call to params | UnsafeDeserialization.rb:116:25:116:33 | yaml_data | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:115:17:115:22 | call to params | user-provided value |
|
|
|
|
|
| UnsafeDeserialization.rb:120:24:120:34 | call to read | UnsafeDeserialization.rb:120:24:120:34 | call to read | UnsafeDeserialization.rb:120:24:120:34 | call to read | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:120:24:120:34 | call to read | value from stdin |
|
|
|
|
|
| UnsafeDeserialization.rb:123:24:123:33 | call to gets | UnsafeDeserialization.rb:123:24:123:33 | call to gets | UnsafeDeserialization.rb:123:24:123:33 | call to gets | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:123:24:123:33 | call to gets | value from stdin |
|
|
|
|
|
| UnsafeDeserialization.rb:126:24:126:32 | call to read | UnsafeDeserialization.rb:126:24:126:32 | call to read | UnsafeDeserialization.rb:126:24:126:32 | call to read | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:126:24:126:32 | call to read | value from stdin |
|
|
|
|
|
| UnsafeDeserialization.rb:129:24:129:27 | call to gets | UnsafeDeserialization.rb:129:24:129:27 | call to gets | UnsafeDeserialization.rb:129:24:129:27 | call to gets | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:129:24:129:27 | call to gets | value from stdin |
|
|
|
|
|
| UnsafeDeserialization.rb:132:24:132:32 | call to readlines | UnsafeDeserialization.rb:132:24:132:32 | call to readlines | UnsafeDeserialization.rb:132:24:132:32 | call to readlines | Unsafe deserialization depends on a $@. | UnsafeDeserialization.rb:132:24:132:32 | call to readlines | value from stdin |
|
|
|
|
|
| YAMLUnsafeDeserialization.rb:5:16:5:35 | ...[...] | YAMLUnsafeDeserialization.rb:5:16:5:21 | call to params | YAMLUnsafeDeserialization.rb:5:16:5:35 | ...[...] | Unsafe deserialization depends on a $@. | YAMLUnsafeDeserialization.rb:5:16:5:21 | call to params | user-provided value |
|
|
|
|
|
| YAMLUnsafeDeserialization.rb:11:23:11:42 | ...[...] | YAMLUnsafeDeserialization.rb:11:23:11:28 | call to params | YAMLUnsafeDeserialization.rb:11:23:11:42 | ...[...] | Unsafe deserialization depends on a $@. | YAMLUnsafeDeserialization.rb:11:23:11:28 | call to params | user-provided value |
|
|
|
|
|
| YAMLUnsafeDeserialization.rb:12:28:12:45 | ...[...] | YAMLUnsafeDeserialization.rb:12:28:12:33 | call to params | YAMLUnsafeDeserialization.rb:12:28:12:45 | ...[...] | Unsafe deserialization depends on a $@. | YAMLUnsafeDeserialization.rb:12:28:12:33 | call to params | user-provided value |
|
|
|
|
|
|