mirror of
https://github.com/github/codeql.git
synced 2025-12-16 16:53:25 +01:00
Python security queries. Choose a precision reflecting actual precision for Security queries.
This commit is contained in:
@@ -4,7 +4,7 @@
|
|||||||
* @kind problem
|
* @kind problem
|
||||||
* @problem.severity error
|
* @problem.severity error
|
||||||
* @sub-severity high
|
* @sub-severity high
|
||||||
* @precision medium
|
* @precision high
|
||||||
* @id py/path-injection
|
* @id py/path-injection
|
||||||
* @tags correctness
|
* @tags correctness
|
||||||
* security
|
* security
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
* @kind problem
|
* @kind problem
|
||||||
* @problem.severity error
|
* @problem.severity error
|
||||||
* @sub-severity high
|
* @sub-severity high
|
||||||
* @precision medium
|
* @precision high
|
||||||
* @id py/command-line-injection
|
* @id py/command-line-injection
|
||||||
* @tags correctness
|
* @tags correctness
|
||||||
* security
|
* security
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
* @kind problem
|
* @kind problem
|
||||||
* @problem.severity error
|
* @problem.severity error
|
||||||
* @sub-severity high
|
* @sub-severity high
|
||||||
* @precision medium
|
* @precision high
|
||||||
* @id py/reflective-xss
|
* @id py/reflective-xss
|
||||||
* @tags security
|
* @tags security
|
||||||
* external/cwe/cwe-079
|
* external/cwe/cwe-079
|
||||||
|
|||||||
@@ -4,7 +4,7 @@
|
|||||||
* malicious SQL code by the user.
|
* malicious SQL code by the user.
|
||||||
* @kind problem
|
* @kind problem
|
||||||
* @problem.severity error
|
* @problem.severity error
|
||||||
* @precision medium
|
* @precision high
|
||||||
* @id py/sql-injection
|
* @id py/sql-injection
|
||||||
* @tags security
|
* @tags security
|
||||||
* external/cwe/cwe-089
|
* external/cwe/cwe-089
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
* @kind problem
|
* @kind problem
|
||||||
* @problem.severity error
|
* @problem.severity error
|
||||||
* @sub-severity high
|
* @sub-severity high
|
||||||
* @precision medium
|
* @precision high
|
||||||
* @id py/code-injection
|
* @id py/code-injection
|
||||||
* @tags security
|
* @tags security
|
||||||
* external/owasp/owasp-a1
|
* external/owasp/owasp-a1
|
||||||
|
|||||||
@@ -3,7 +3,7 @@
|
|||||||
* @description Using broken or weak cryptographic algorithms can compromise security.
|
* @description Using broken or weak cryptographic algorithms can compromise security.
|
||||||
* @kind problem
|
* @kind problem
|
||||||
* @problem.severity warning
|
* @problem.severity warning
|
||||||
* @precision medium
|
* @precision high
|
||||||
* @id py/weak-cryptographic-algorithm
|
* @id py/weak-cryptographic-algorithm
|
||||||
* @tags security
|
* @tags security
|
||||||
* external/cwe/cwe-327
|
* external/cwe/cwe-327
|
||||||
|
|||||||
@@ -5,7 +5,7 @@
|
|||||||
* @id py/unsafe-deserialization
|
* @id py/unsafe-deserialization
|
||||||
* @problem.severity error
|
* @problem.severity error
|
||||||
* @sub-severity high
|
* @sub-severity high
|
||||||
* @precision medium
|
* @precision high
|
||||||
* @tags external/cwe/cwe-502
|
* @tags external/cwe/cwe-502
|
||||||
* security
|
* security
|
||||||
* serialization
|
* serialization
|
||||||
|
|||||||
Reference in New Issue
Block a user