mirror of
https://github.com/github/codeql.git
synced 2026-04-29 18:55:14 +02:00
Tag all security queries in supported languages' experimental directories with an experimental tag
This commit is contained in:
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/insecure-spring-actuator-config
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-016
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/spring-boot-exposed-actuators
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-16
|
||||
*/
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
* @precision high
|
||||
* @id java/log4j-injection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-020
|
||||
* external/cwe/cwe-074
|
||||
* external/cwe/cwe-400
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision medium
|
||||
* @id java/openstream-called-on-tainted-url
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-036
|
||||
*/
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
* @precision high
|
||||
* @id java/file-path-injection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe-073
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/command-line-injection-experimental
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-078
|
||||
* external/cwe/cwe-088
|
||||
*/
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
* @precision high
|
||||
* @id java/mybatis-annotation-sql-injection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-089
|
||||
*/
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
* @precision high
|
||||
* @id java/mybatis-xml-sql-injection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-089
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/beanshell-injection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-094
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/android-insecure-dex-loading
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-094
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/jshell-injection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-094
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/javaee-expression-injection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-094
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/jython-injection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-094
|
||||
* external/cwe/cwe-095
|
||||
*/
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/unsafe-eval
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-094
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @precision high
|
||||
* @id java/spring-view-manipulation-implicit
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-094
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @precision high
|
||||
* @id java/spring-view-manipulation
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-094
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @precision medium
|
||||
* @id java/tomcat-disabled-httponly
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-1004
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision medium
|
||||
* @id java/sensitive-cookie-not-httponly
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-1004
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @id java/insecure-webview-resource-response
|
||||
* @problem.severity error
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-200
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @id java/sensitive-android-file-leak
|
||||
* @problem.severity warning
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-200
|
||||
*/
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@
|
||||
* @precision medium
|
||||
* @id java/possible-timing-attack-against-signature
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-208
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/timing-attack-against-headers-value
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-208
|
||||
*/
|
||||
|
||||
|
||||
@@ -10,6 +10,7 @@
|
||||
* @precision high
|
||||
* @id java/timing-attack-against-signature
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-208
|
||||
*/
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
* @precision medium
|
||||
* @id java/jxbrowser/disabled-certificate-validation
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-295
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/ignored-hostname-verification
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-297
|
||||
*/
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
* @precision medium
|
||||
* @id java/insecure-ldaps-endpoint
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-297
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/disabled-certificate-revocation-checking
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-299
|
||||
*/
|
||||
|
||||
|
||||
@@ -5,6 +5,7 @@
|
||||
* @problem.severity error
|
||||
* @id java/hardcoded-jwt-key
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-321
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/unsafe-tls-version
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-327
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @precision high
|
||||
* @id java/unvalidated-cors-origin-set
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-346
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/ip-address-spoofing
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-348
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/jsonp-injection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-352
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @id java/thread-resource-abuse
|
||||
* @problem.severity warning
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-400
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/unsafe-reflection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-470
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @precision medium
|
||||
* @id java/main-method-in-enterprise-bean
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-489
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @precision medium
|
||||
* @id java/main-method-in-web-components
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-489
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/struts-development-mode
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-489
|
||||
*/
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@
|
||||
* @precision high
|
||||
* @id java/unsafe-deserialization-rmi
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-502
|
||||
*/
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
* @precision high
|
||||
* @id java/unsafe-deserialization-spring-exporter-in-configuration-class
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-502
|
||||
*/
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
* @precision high
|
||||
* @id java/unsafe-deserialization-spring-exporter-in-xml-configuration
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-502
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @precision medium
|
||||
* @id java/insecure-ldap-auth
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-522
|
||||
* external/cwe/cwe-319
|
||||
*/
|
||||
|
||||
@@ -9,6 +9,7 @@
|
||||
* @precision medium
|
||||
* @id java/server-directory-listing
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-548
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/unsafe-url-forward-dispatch-load
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe-552
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @precision high
|
||||
* @id java/credentials-in-properties
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-555
|
||||
* external/cwe/cwe-256
|
||||
* external/cwe/cwe-260
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @precision medium
|
||||
* @id java/password-in-configuration
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-555
|
||||
* external/cwe/cwe-256
|
||||
* external/cwe/cwe-260
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @precision medium
|
||||
* @id java/sensitive-query-with-get
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-598
|
||||
*/
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@
|
||||
* @precision medium
|
||||
* @id java/uncaught-servlet-exception
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-600
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/spring-unvalidated-url-redirection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-601
|
||||
*/
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
* @precision high
|
||||
* @id java/xxe-with-experimental-sinks
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-611
|
||||
*/
|
||||
|
||||
|
||||
@@ -10,6 +10,7 @@
|
||||
* @precision medium
|
||||
* @id java/xxe-local-experimental-sinks
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-611
|
||||
*/
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/permissive-dot-regex
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe-625
|
||||
* external/cwe-863
|
||||
*/
|
||||
|
||||
@@ -7,6 +7,7 @@
|
||||
* @precision high
|
||||
* @id java/xquery-injection
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-652
|
||||
*/
|
||||
|
||||
|
||||
@@ -4,6 +4,7 @@
|
||||
* @kind problem
|
||||
* @problem.severity error
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-665
|
||||
* @precision high
|
||||
* @id java/insecure-rmi-jmx-server-initialization
|
||||
|
||||
@@ -9,6 +9,7 @@
|
||||
* @precision medium
|
||||
* @id java/android/nfe-local-android-dos
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-755
|
||||
*/
|
||||
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
* @precision low
|
||||
* @id java/hash-without-salt
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-759
|
||||
*/
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
* @precision medium
|
||||
* @id java/incorrect-url-verification
|
||||
* @tags security
|
||||
* experimental
|
||||
* external/cwe/cwe-939
|
||||
*/
|
||||
|
||||
|
||||
Reference in New Issue
Block a user