mirror of
https://github.com/github/codeql.git
synced 2026-04-24 16:25:15 +02:00
Remove generated sinks and sources
This commit is contained in:
@@ -1,240 +1,6 @@
|
||||
# THIS FILE IS AN AUTO-GENERATED MODELS AS DATA FILE. DO NOT EDIT.
|
||||
# Definitions of models for the Struts Models framework.
|
||||
extensions:
|
||||
- addsTo:
|
||||
pack: codeql/java-all
|
||||
extensible: sinkModel
|
||||
data:
|
||||
- ["com.opensymphony.xwork2.config.providers", "InterceptorBuilder", true, "constructInterceptorReference", "(InterceptorLocator,String,Map,Location,ObjectFactory)", "", "Argument[2]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.config", "ContainerProvider", true, "init", "(Configuration)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.config", "ContainerProvider", true, "init", "(Configuration)", "", "Argument[this]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.config", "PackageProvider", true, "init", "(Configuration)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.config", "PackageProvider", true, "init", "(Configuration)", "", "Argument[this]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.conversion.impl", "XWorkConverter", true, "getConversionErrorMessage", "(String,Class,ValueStack)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.factory", "InterceptorFactory", true, "buildInterceptor", "(InterceptorConfig,Map)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.factory", "ValidatorFactory", true, "buildValidator", "(String,Map,Map)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.interceptor", "Interceptor", true, "intercept", "(ActionInvocation)", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.interceptor", "PreResultListener", true, "beforeResult", "(ActionInvocation,String)", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.interceptor", "PreResultListener", true, "beforeResult", "(ActionInvocation,String)", "", "Argument[this]", "response-splitting", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.interceptor", "WithLazyParams$LazyParamInjector", true, "injectParams", "(Interceptor,Map,ActionContext)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.classloader", "ResourceStore", true, "read", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "find", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "find", "(String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAll", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAll", "(String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAllClasses", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAllProperties", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAllProperties", "(String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAllStrings", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAllStrings", "(String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAvailableClasses", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAvailableProperties", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAvailableProperties", "(String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAvailableStrings", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findAvailableStrings", "(String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findClass", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findPackages", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findPackages", "(String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findPackagesMap", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findPackagesMap", "(String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findProperties", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findProperties", "(String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findString", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "findString", "(String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "getResourcesMap", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "getResourcesMap", "(String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "mapAllClasses", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "mapAllProperties", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "mapAllStrings", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "mapAvailableClasses", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "mapAvailableProperties", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "ResourceFinder", true, "mapAvailableStrings", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "UrlSet$FileProtocolNormalizer", true, "normalizeToFileProtocol", "(URL)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.finder", "UrlSet", true, "excludePaths", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.fs", "FileRevision", true, "build", "(URL)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.fs", "JarEntryRevision", true, "build", "(URL,FileManager)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.reflection", "ReflectionProvider", true, "getValue", "(String,Map,Object)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.reflection", "ReflectionProvider", true, "setProperties", "(Map,Object)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.reflection", "ReflectionProvider", true, "setProperties", "(Map,Object,Map)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.reflection", "ReflectionProvider", true, "setProperties", "(Map,Object,Map,boolean)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.reflection", "ReflectionProvider", true, "setProperty", "(String,Object,Object,Map)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.reflection", "ReflectionProvider", true, "setProperty", "(String,Object,Object,Map,boolean)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util.reflection", "ReflectionProvider", true, "setValue", "(String,Map,Object,Object)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "TextParseUtil$ParsedValueEvaluator", true, "evaluate", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "TextParser", true, "evaluate", "(char[],String,ParsedValueEvaluator,int)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "ValueStack", true, "findString", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "ValueStack", true, "findString", "(String,boolean)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "ValueStack", true, "findValue", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "ValueStack", true, "findValue", "(String,Class)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "ValueStack", true, "findValue", "(String,Class,boolean)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "ValueStack", true, "findValue", "(String,boolean)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "ValueStack", true, "setParameter", "(String,Object)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "ValueStack", true, "setValue", "(String,Object)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "ValueStack", true, "setValue", "(String,Object,boolean)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "ConditionalVisitorFieldValidator", true, "validateExpression", "(Object)", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "DoubleRangeFieldValidator", true, "getMaxExclusive", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "DoubleRangeFieldValidator", true, "getMaxInclusive", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "DoubleRangeFieldValidator", true, "getMinExclusive", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "DoubleRangeFieldValidator", true, "getMinInclusive", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "RangeValidatorSupport", true, "getMax", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "RangeValidatorSupport", true, "getMin", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "RegexFieldValidator", true, "getRegex", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "RegexFieldValidator", true, "isCaseSensitive", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "RegexFieldValidator", true, "isTrimed", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "RequiredStringValidator", true, "setTrimExpression", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "StringLengthFieldValidator", true, "getMaxLength", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "StringLengthFieldValidator", true, "getMinLength", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.validator.validators", "StringLengthFieldValidator", true, "isTrim", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "Action", true, "execute", "()", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "Action", true, "execute", "()", "", "Argument[this]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "ActionProxyFactory", true, "createActionProxy", "(ActionInvocation,String,String,String,boolean,boolean)", "", "Argument[1]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "ActionProxyFactory", true, "createActionProxy", "(ActionInvocation,String,String,String,boolean,boolean)", "", "Argument[1]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "ActionProxyFactory", true, "createActionProxy", "(String,String,String,Map)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "ActionProxyFactory", true, "createActionProxy", "(String,String,String,Map)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "ActionProxyFactory", true, "createActionProxy", "(String,String,String,Map,boolean,boolean)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "ActionProxyFactory", true, "createActionProxy", "(String,String,String,Map,boolean,boolean)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "DefaultActionInvocation", true, "createResult", "()", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "DefaultActionInvocation", true, "createResult", "()", "", "Argument[this]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "DefaultActionProxyFactory", true, "createActionProxy", "(ActionInvocation,String,String,boolean,boolean)", "", "Argument[1]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "DefaultActionProxyFactory", true, "createActionProxy", "(ActionInvocation,String,String,boolean,boolean)", "", "Argument[1]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "DefaultActionProxyFactory", true, "createActionProxy", "(String,String,Map)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "DefaultActionProxyFactory", true, "createActionProxy", "(String,String,Map)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "DefaultActionProxyFactory", true, "createActionProxy", "(String,String,Map,boolean,boolean)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "DefaultActionProxyFactory", true, "createActionProxy", "(String,String,Map,boolean,boolean)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "FileManager", true, "getAllPhysicalUrls", "(URL)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "FileManager", true, "loadFile", "(URL)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "FileManager", true, "loadFile", "(URL)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "FileManager", true, "monitorFile", "(URL)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "FileManager", true, "monitorFile", "(URL)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "FileManager", true, "normalizeToFileProtocol", "(URL)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "LocalizedTextProvider", true, "findText", "(Class,String,Locale)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "LocalizedTextProvider", true, "findText", "(Class,String,Locale,String,Object[])", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "LocalizedTextProvider", true, "findText", "(Class,String,Locale,String,Object[])", "", "Argument[3]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "LocalizedTextProvider", true, "findText", "(Class,String,Locale,String,Object[],ValueStack)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "LocalizedTextProvider", true, "findText", "(Class,String,Locale,String,Object[],ValueStack)", "", "Argument[3]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "LocalizedTextProvider", true, "findText", "(ResourceBundle,String,Locale)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "LocalizedTextProvider", true, "findText", "(ResourceBundle,String,Locale)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "LocalizedTextProvider", true, "findText", "(ResourceBundle,String,Locale,String,Object[])", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "LocalizedTextProvider", true, "findText", "(ResourceBundle,String,Locale,String,Object[])", "", "Argument[3]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "LocalizedTextProvider", true, "findText", "(ResourceBundle,String,Locale,String,Object[],ValueStack)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "LocalizedTextProvider", true, "findText", "(ResourceBundle,String,Locale,String,Object[],ValueStack)", "", "Argument[3]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "ObjectFactory", true, "buildInterceptor", "(InterceptorConfig,Map)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "ObjectFactory", true, "buildValidator", "(String,Map,Map)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "Result", true, "execute", "(ActionInvocation)", "", "Argument[this]", "information-leak", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "Result", true, "execute", "(ActionInvocation)", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "Result", true, "execute", "(ActionInvocation)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "Result", true, "execute", "(ActionInvocation)", "", "Argument[this]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "Result", true, "execute", "(ActionInvocation)", "", "Argument[this]", "response-splitting", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandler", true, "handleUnknownAction", "(String,String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandler", true, "handleUnknownAction", "(String,String)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandler", true, "handleUnknownAction", "(String,String)", "", "Argument[1]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandler", true, "handleUnknownAction", "(String,String)", "", "Argument[1]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandler", true, "handleUnknownResult", "(ActionContext,String,ActionConfig,String)", "", "Argument[1]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandler", true, "handleUnknownResult", "(ActionContext,String,ActionConfig,String)", "", "Argument[1]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandler", true, "handleUnknownResult", "(ActionContext,String,ActionConfig,String)", "", "Argument[3]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandler", true, "handleUnknownResult", "(ActionContext,String,ActionConfig,String)", "", "Argument[3]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandler", true, "handleUnknownResult", "(ActionContext,String,ActionConfig,String)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandler", true, "handleUnknownResult", "(ActionContext,String,ActionConfig,String)", "", "Argument[this]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandlerManager", true, "handleUnknownAction", "(String,String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandlerManager", true, "handleUnknownAction", "(String,String)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandlerManager", true, "handleUnknownAction", "(String,String)", "", "Argument[1]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandlerManager", true, "handleUnknownAction", "(String,String)", "", "Argument[1]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandlerManager", true, "handleUnknownResult", "(ActionContext,String,ActionConfig,String)", "", "Argument[1]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandlerManager", true, "handleUnknownResult", "(ActionContext,String,ActionConfig,String)", "", "Argument[1]", "request-forgery", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandlerManager", true, "handleUnknownResult", "(ActionContext,String,ActionConfig,String)", "", "Argument[3]", "path-injection", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "UnknownHandlerManager", true, "handleUnknownResult", "(ActionContext,String,ActionConfig,String)", "", "Argument[3]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.components", "Component", true, "addParameter", "(String,Object)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "Component", true, "copyParams", "(Map)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "Component", true, "end", "(Writer,String)", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "Component", true, "findString", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "Component", true, "start", "(Writer)", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "ContextBean", true, "setVar", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "Form", true, "getValidators", "(String)", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "UIBean", true, "evaluateExtraParams", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "UIBean", true, "evaluateParams", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "UIBean", true, "getTemplateDir", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "UIBean", true, "getTheme", "()", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "UrlProvider", true, "determineActionURL", "(String,String,String,HttpServletRequest,HttpServletResponse,Map,String,boolean,boolean,boolean,boolean)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "UrlProvider", true, "determineActionURL", "(String,String,String,HttpServletRequest,HttpServletResponse,Map,String,boolean,boolean,boolean,boolean)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "UrlProvider", true, "determineActionURL", "(String,String,String,HttpServletRequest,HttpServletResponse,Map,String,boolean,boolean,boolean,boolean)", "", "Argument[2]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "UrlProvider", true, "determineNamespace", "(String,ValueStack,HttpServletRequest)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.components", "UrlProvider", true, "findString", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.config", "StrutsXmlConfigurationProvider", true, "StrutsXmlConfigurationProvider", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.config", "StrutsXmlConfigurationProvider", true, "StrutsXmlConfigurationProvider", "(String,ServletContext)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.config", "StrutsXmlConfigurationProvider", true, "StrutsXmlConfigurationProvider", "(String,boolean,ServletContext)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.convention", "DefaultClassFinder", true, "DefaultClassFinder", "(ClassLoaderInterface,Collection,boolean,Set,Test)", "", "Argument[1]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.convention", "ResultMapBuilder", true, "build", "(Class,Action,String,PackageConfig)", "", "Argument[2]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.convention", "ResultMapBuilder", true, "build", "(Class,Action,String,PackageConfig)", "", "Argument[2]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.dispatcher.multipart", "MultiPartRequest", true, "parse", "(HttpServletRequest,String)", "", "Argument[1]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.dispatcher.multipart", "MultiPartRequestWrapper", true, "MultiPartRequestWrapper", "(MultiPartRequest,HttpServletRequest,String,LocaleProvider)", "", "Argument[2]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.dispatcher.multipart", "MultiPartRequestWrapper", true, "MultiPartRequestWrapper", "(MultiPartRequest,HttpServletRequest,String,LocaleProvider,boolean)", "", "Argument[2]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.dispatcher", "PrepareOperations", true, "decrementRecursionCounter", "(HttpServletRequest,String,Runnable)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.dispatcher", "PrepareOperations", true, "incrementRecursionCounter", "(HttpServletRequest,String)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.dispatcher", "RequestMap", true, "get", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.dispatcher", "RequestMap", true, "remove", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.interceptor.csp", "CspSettings", true, "addCspHeaders", "(HttpServletRequest,HttpServletResponse)", "", "Argument[this]", "response-splitting", "df-generated"]
|
||||
- ["org.apache.struts2.jasper.compiler", "SmapUtil", true, "installSmap", "(String[])", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.jasper.runtime", "JspRuntimeLibrary", true, "convert", "(String,String,Class,Class)", "", "Argument[1]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.jasper.runtime", "JspRuntimeLibrary", true, "introspecthelper", "(Object,String,String,ServletRequest,String,boolean)", "", "Argument[2]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.jasper.servlet", "JasperLoader", true, "JasperLoader", "(URL[],ClassLoader,PermissionCollection,CodeSource)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.jasper", "JspC", true, "scanFiles", "(File)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.jasper", "JspCompilationContext", true, "checkOutputDir", "()", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.jasper", "JspCompilationContext", true, "getJspLoader", "()", "", "Argument[this]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.jasper", "JspCompilationContext", true, "getRealPath", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.jasper", "JspCompilationContext", true, "getRealPath", "(String)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.jasper", "JspCompilationContext", true, "getResourcePaths", "(String)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.jasper", "JspCompilationContext", true, "getResourcePaths", "(String)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.junit.util", "TestUtils", true, "assertEquals", "(URL,String)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.junit.util", "TestUtils", true, "compare", "(URL,String)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.junit.util", "TestUtils", true, "normalize", "(URL)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.junit.util", "TestUtils", true, "readContent", "(URL)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.junit.util", "TestUtils", true, "readContent", "(URL,Charset)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.rest", "HttpHeaders", true, "apply", "(HttpServletRequest,HttpServletResponse,Object)", "", "Argument[this]", "response-splitting", "df-generated"]
|
||||
- ["org.apache.struts2.result", "StrutsResultSupport", true, "doExecute", "(String,ActionInvocation)", "", "Argument[0]", "information-leak", "df-generated"]
|
||||
- ["org.apache.struts2.result", "StrutsResultSupport", true, "doExecute", "(String,ActionInvocation)", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.showcase.filedownload", "FileDownloadAction", true, "getInputStream", "()", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.showcase.filedownload", "FileDownloadAction", true, "getInputStream", "()", "", "Argument[this]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.spring", "ClassReloadingXMLWebApplicationContext", true, "setupReloading", "(String[],String,ServletContext,boolean)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.spring", "ClassReloadingXMLWebApplicationContext", true, "setupReloading", "(String[],String,ServletContext,boolean)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.util", "StrutsTestCaseHelper", true, "initDispatcher", "(ServletContext,Map)", "", "Argument[1]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.util", "StrutsUtil", true, "translateVariables", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.util", "TextProviderHelper", true, "getText", "(String,String,List,ValueStack)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.util", "TextProviderHelper", true, "getText", "(String,String,List,ValueStack)", "", "Argument[2]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.util", "TextProviderHelper", true, "getText", "(String,String,ValueStack)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.validators", "DWRValidator", true, "doPost", "(String,String,Map)", "", "Argument[0]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.validators", "DWRValidator", true, "doPost", "(String,String,Map)", "", "Argument[0]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.views.freemarker", "FreemarkerManager", true, "init", "(ServletContext)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.views.jasperreports", "ValueStackDataSource", true, "ValueStackDataSource", "(ValueStack,String,boolean)", "", "Argument[1]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.views.jasperreports", "ValueStackDataSource", true, "ValueStackDataSource", "(ValueStack,String,boolean)", "", "Argument[this]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.views.jasperreports", "ValueStackShadowMap", true, "containsKey", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.views.jasperreports", "ValueStackShadowMap", true, "get", "(String)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.views.jsp.ui", "OgnlTool", true, "findValue", "(String,Object)", "", "Argument[0]", "ognl-injection", "df-generated"]
|
||||
- ["org.apache.struts2.views.velocity", "VelocityManager", true, "loadConfiguration", "(ServletContext)", "", "Argument[this]", "path-injection", "df-generated"]
|
||||
- ["org.apache.struts2.views.velocity", "VelocityManager", true, "loadConfiguration", "(ServletContext)", "", "Argument[this]", "request-forgery", "df-generated"]
|
||||
- ["org.apache.struts2.views.velocity", "VelocityStrutsUtil", true, "evaluate", "(String)", "", "Argument[0]", "template-injection", "df-generated"]
|
||||
- addsTo:
|
||||
pack: codeql/java-all
|
||||
extensible: sourceModel
|
||||
data:
|
||||
- ["com.opensymphony.xwork2.util", "TextParseUtil$ParsedValueEvaluator", true, "evaluate", "(String)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["com.opensymphony.xwork2.util", "TextParser", true, "evaluate", "(char[],String,ParsedValueEvaluator,int)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["com.opensymphony.xwork2", "ActionContext", true, "containsValueStack", "(Map)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.components", "Component", true, "end", "(Writer,String)", "", "Argument[0]", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.components", "Include", true, "getContextRelativePath", "(ServletRequest,String)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.components", "UrlProvider", true, "determineActionURL", "(String,String,String,HttpServletRequest,HttpServletResponse,Map,String,boolean,boolean,boolean,boolean)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.components", "UrlRenderer", true, "renderUrl", "(Writer,UrlProvider)", "", "Argument[0]", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.interceptor", "PrincipalProxy", true, "getRemoteUser", "()", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.portlet.dispatcher", "Jsr168Dispatcher", true, "serviceAction", "(PortletRequest,PortletResponse,Map,Map,Map,Map,String,PortletPhase)", "", "Argument[3].Element", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.util", "StrutsUtil", true, "buildUrl", "(String)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.util", "URLBean", true, "getURL", "()", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.util", "URLBean", true, "toString", "()", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.views.util", "ResourceUtil", true, "getResourceBase", "(HttpServletRequest)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.views.util", "UrlHelper", true, "buildUrl", "(String,HttpServletRequest,HttpServletResponse,Map)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.views.util", "UrlHelper", true, "buildUrl", "(String,HttpServletRequest,HttpServletResponse,Map,String,boolean,boolean)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.views.util", "UrlHelper", true, "buildUrl", "(String,HttpServletRequest,HttpServletResponse,Map,String,boolean,boolean,boolean)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2.views.util", "UrlHelper", true, "buildUrl", "(String,HttpServletRequest,HttpServletResponse,Map,String,boolean,boolean,boolean,boolean)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2", "RequestUtils", true, "getServletPath", "(HttpServletRequest)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- ["org.apache.struts2", "RequestUtils", true, "getUri", "(HttpServletRequest)", "", "ReturnValue", "remote", "df-generated"]
|
||||
- addsTo:
|
||||
pack: codeql/java-all
|
||||
extensible: summaryModel
|
||||
|
||||
Reference in New Issue
Block a user