mirror of
https://github.com/github/codeql.git
synced 2026-04-29 02:35:15 +02:00
Renamed RmiUnsafeDeserialization.ql -> UnsafeDeserializationRmi.ql
This commit is contained in:
@@ -1 +0,0 @@
|
||||
experimental/Security/CWE/CWE-502/RmiUnsafeDeserialization.ql
|
||||
@@ -5,8 +5,8 @@ import java.rmi.RemoteException;
|
||||
import java.rmi.registry.LocateRegistry;
|
||||
import java.rmi.registry.Registry;
|
||||
|
||||
public class RmiUnsafeDeserialization {
|
||||
|
||||
public class UnsafeDeserializationRmi {
|
||||
|
||||
// BAD (bind a remote object that has a vulnerable method that takes Object)
|
||||
public static void testRegistryBindWithObjectParameter() throws Exception {
|
||||
Registry registry = LocateRegistry.createRegistry(1099);
|
||||
@@ -55,4 +55,4 @@ class SafeRemoteObject implements SafeRemoteObjectInterface {
|
||||
public void take(String s) throws RemoteException {}
|
||||
public void take(ObjectInputStream ois) throws RemoteException {}
|
||||
public void safeMethod(Object object) {} // this method is not declared in SafeRemoteObjectInterface
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
experimental/Security/CWE/CWE-502/UnsafeDeserializationRmi.ql
|
||||
Reference in New Issue
Block a user