From 7712ec2523c3178720aa648532f032b54ba4cf02 Mon Sep 17 00:00:00 2001 From: Ed Minnix Date: Sat, 12 Nov 2022 09:54:26 -0500 Subject: [PATCH] Java: setJavascriptEnabled query change notes --- .../CWE/CWE-079/AndroidWebViewSettingsEnabledJavaScript.ql | 2 +- .../2022-11-12-websettings-setjavascript-enabled.md | 4 ++++ 2 files changed, 5 insertions(+), 1 deletion(-) create mode 100644 java/ql/src/change-notes/2022-11-12-websettings-setjavascript-enabled.md diff --git a/java/ql/src/Security/CWE/CWE-079/AndroidWebViewSettingsEnabledJavaScript.ql b/java/ql/src/Security/CWE/CWE-079/AndroidWebViewSettingsEnabledJavaScript.ql index 4483f80ad38..7b33f9313db 100644 --- a/java/ql/src/Security/CWE/CWE-079/AndroidWebViewSettingsEnabledJavaScript.ql +++ b/java/ql/src/Security/CWE/CWE-079/AndroidWebViewSettingsEnabledJavaScript.ql @@ -1,7 +1,7 @@ /** * @name Android WebView JavaScript settings * @kind problem - * @id java/android-websettings-javascript + * @id java/android-websettings-javascript-enabled * @problem.severity warning * @security-severity 6.1 * @precision high diff --git a/java/ql/src/change-notes/2022-11-12-websettings-setjavascript-enabled.md b/java/ql/src/change-notes/2022-11-12-websettings-setjavascript-enabled.md new file mode 100644 index 00000000000..58579f006c4 --- /dev/null +++ b/java/ql/src/change-notes/2022-11-12-websettings-setjavascript-enabled.md @@ -0,0 +1,4 @@ +--- +category: newQuery +--- +* Added a new query, `java/android-websettings-javascript-enabled`, to detect if JavaScript execution is enabled in an Android WebView.