Fix credential-username

This commit is contained in:
Ed Minnix
2023-08-16 01:38:44 -04:00
parent 96d6ecb108
commit f783ca7940
17 changed files with 46 additions and 46 deletions

View File

@@ -3,7 +3,7 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["com.sun.jndi.ldap", "DigestClientId", False, "DigestClientId", "(int, String, int, String, Control[], OutputStream, String, String, Object, Hashtable)", "credential-username", "Argument[7]", "manual"]
- ["com.sun.jndi.ldap", "LdapClient", False, "getInstance", "(boolean, String, int, String, int, int, OutputStream, int, String, Control[], String, String, Object, Hashtable)", "credential-username", "Argument[11]", "manual"]
- ["com.sun.jndi.ldap", "LdapPoolManager", False, "getLdapClient", "(String, int, String, int, int, OutputStream, int, String, Control[], String, String, Object, Hashtable)", "credential-username", "Argument[10]", "manual"]
- ["com.sun.jndi.ldap", "SimpleClientId", False, "SimpleClientId", "(int, String, int, String, Control[], OutputStream, String, String, Object)", "credential-username", "Argument[7]", "manual"]
- ["com.sun.jndi.ldap", "DigestClientId", False, "DigestClientId", "(int, String, int, String, Control[], OutputStream, String, String, Object, Hashtable)", "", "Argument[7]", "credential-username", "manual"]
- ["com.sun.jndi.ldap", "LdapClient", False, "getInstance", "(boolean, String, int, String, int, int, OutputStream, int, String, Control[], String, String, Object, Hashtable)", "", "Argument[11]", "credential-username", "manual"]
- ["com.sun.jndi.ldap", "LdapPoolManager", False, "getLdapClient", "(String, int, String, int, int, OutputStream, int, String, Control[], String, String, Object, Hashtable)", "", "Argument[10]", "credential-username", "manual"]
- ["com.sun.jndi.ldap", "SimpleClientId", False, "SimpleClientId", "(int, String, int, String, Control[], OutputStream, String, String, Object)", "", "Argument[7]", "credential-username", "manual"]

View File

@@ -3,6 +3,6 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["com.sun.rowset", "JdbcRowSetImpl", False, "JdbcRowSetImpl", "(String, String, String)", "credential-username", "Argument[1]", "manual"]
- ["com.sun.rowset", "JdbcRowSetImpl", False, "JdbcRowSetImpl", "(String, String, String)", "", "Argument[2]", "credential-password", "manual"]
- ["com.sun.rowset", "JdbcRowSetImpl", False, "setPassword", "(String)", "", "Argument[0]", "credential-password", "manual"]
- ["com.sun.rowset", "JdbcRowSetImpl", False, "JdbcRowSetImpl", "(String, String, String)", "", "Argument[1]", "credential-username", "manual"]

View File

@@ -6,5 +6,5 @@ extensions:
- ["com.sun.security.ntlm", "Client", False, "Client", "(String, String, String, String, char[])", "", "Argument[4]", "credential-password", "manual"]
- ["com.sun.security.ntlm", "NTLM", False, "getP1", "(char[])", "", "Argument[0]", "credential-password", "manual"]
- ["com.sun.security.ntlm", "NTLM", False, "getP2", "(char[])", "", "Argument[0]", "credential-password", "manual"]
- ["com.sun.security.ntlm", "Client", False, "Client", "(String, String, String, String, char[])", "credential-username", "Argument[2]", "manual"]
- ["com.sun.security.ntlm", "Server", False, "getPassword", "(String, String)", "credential-username", "Argument[1]", "manual"]
- ["com.sun.security.ntlm", "Client", False, "Client", "(String, String, String, String, char[])", "", "Argument[2]", "credential-username", "manual"]
- ["com.sun.security.ntlm", "Server", False, "getPassword", "(String, String)", "", "Argument[1]", "credential-username", "manual"]

View File

@@ -5,4 +5,4 @@ extensions:
data:
- ["com.sun.security.sasl.digest", "DigestMD5Base", False, "generateResponseValue", "(String, String, String, String, String, char[], byte[], byte[], int, byte[])", "", "Argument[5]", "credential-password", "manual"]
- ["com.sun.security.sasl.digest", "DigestMD5Server", False, "generateResponseAuth", "(String, char[], byte[], int, byte[])", "", "Argument[1]", "credential-password", "manual"]
- ["com.sun.security.sasl.digest", "DigestMD5Server", False, "generateResponseAuth", "(String, char[], byte[], int, byte[])", "credential-username", "Argument[0]", "manual"]
- ["com.sun.security.sasl.digest", "DigestMD5Server", False, "generateResponseAuth", "(String, char[], byte[], int, byte[])", "", "Argument[0]", "credential-username", "manual"]

View File

@@ -4,4 +4,4 @@ extensions:
extensible: sinkModel
data:
- ["com.sun.tools.internal.ws.wscompile", "AuthInfo", False, "AuthInfo", "(URL, String, String)", "", "Argument[2]", "credential-password", "manual"]
- ["com.sun.tools.internal.ws.wscompile", "AuthInfo", False, "AuthInfo", "(URL, String, String)", "credential-username", "Argument[1]", "manual"]
- ["com.sun.tools.internal.ws.wscompile", "AuthInfo", False, "AuthInfo", "(URL, String, String)", "", "Argument[1]", "credential-username", "manual"]

View File

@@ -26,7 +26,7 @@ extensions:
- ["java.net", "URLClassLoader", False, "URLClassLoader", "(URL[],ClassLoader,URLStreamHandlerFactory)", "", "Argument[0]", "request-forgery", "manual"]
- ["java.net", "URLClassLoader", False, "URLClassLoader", "(URL[],ClassLoader)", "", "Argument[0]", "request-forgery", "manual"]
- ["java.net", "URLClassLoader", False, "URLClassLoader", "(URL[])", "", "Argument[0]", "request-forgery", "manual"]
- ["java.net", "PasswordAuthentication", False, "PasswordAuthentication", "(String, char[])", "credential-username", "Argument[0]", "manual"]
- ["java.net", "PasswordAuthentication", False, "PasswordAuthentication", "(String, char[])", "", "Argument[0]", "credential-username", "manual"]
- addsTo:
pack: codeql/java-all
extensible: summaryModel

View File

@@ -17,7 +17,7 @@ extensions:
- ["java.sql", "Statement", True, "executeLargeUpdate", "", "", "Argument[0]", "sql-injection", "manual"]
- ["java.sql", "Statement", True, "executeQuery", "", "", "Argument[0]", "sql-injection", "manual"]
- ["java.sql", "Statement", True, "executeUpdate", "", "", "Argument[0]", "sql-injection", "manual"]
- ["java.sql", "DriverManager", False, "getConnection", "(String, String, String)", "credential-username", "Argument[1]", "manual"]
- ["java.sql", "DriverManager", False, "getConnection", "(String, String, String)", "", "Argument[1]", "credential-username", "manual"]
- addsTo:
pack: codeql/java-all
extensible: summaryModel

View File

@@ -3,5 +3,5 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["javax.print.attribute.standard", "JobOriginatingUserName", False, "JobOriginatingUserName", "(String, Locale)", "credential-username", "Argument[0]", "manual"]
- ["javax.print.attribute.standard", "RequestingUserName", False, "RequestingUserName", "(String, Locale)", "credential-username", "Argument[0]", "manual"]
- ["javax.print.attribute.standard", "JobOriginatingUserName", False, "JobOriginatingUserName", "(String, Locale)", "", "Argument[0]", "credential-username", "manual"]
- ["javax.print.attribute.standard", "RequestingUserName", False, "RequestingUserName", "(String, Locale)", "", "Argument[0]", "credential-username", "manual"]

View File

@@ -3,10 +3,10 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["javax.sql", "ConnectionPoolDataSource", False, "getPooledConnection", "(String, String)", "credential-username", "Argument[0]", "manual"]
- ["javax.sql", "DataSource", False, "getConnection", "(String, String)", "credential-username", "Argument[0]", "manual"]
- ["javax.sql", "XADataSource", False, "getXAConnection", "(String, String)", "credential-username", "Argument[0]", "manual"]
- ["javax.sql", "ConnectionPoolDataSource", False, "getPooledConnection", "(String, String)", "", "Argument[1]", "credential-password", "manual"]
- ["javax.sql", "DataSource", False, "getConnection", "(String, String)", "", "Argument[1]", "credential-password", "manual"]
- ["javax.sql", "RowSet", False, "setPassword", "(String)", "", "Argument[0]", "credential-password", "manual"]
- ["javax.sql", "XADataSource", False, "getXAConnection", "(String, String)", "", "Argument[1]", "credential-password", "manual"]
- ["javax.sql", "ConnectionPoolDataSource", False, "getPooledConnection", "(String, String)", "", "Argument[0]", "credential-username", "manual"]
- ["javax.sql", "DataSource", False, "getConnection", "(String, String)", "", "Argument[0]", "credential-username", "manual"]
- ["javax.sql", "XADataSource", False, "getXAConnection", "(String, String)", "", "Argument[0]", "credential-username", "manual"]

View File

@@ -3,6 +3,6 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["sun.jvmstat.perfdata.monitor.protocol.local", "LocalVmManager", False, "LocalVmManager", "(String)", "credential-username", "Argument[0]", "manual"]
- ["sun.jvmstat.perfdata.monitor.protocol.local", "PerfDataFile", False, "getFile", "(String, int)", "credential-username", "Argument[0]", "manual"]
- ["sun.jvmstat.perfdata.monitor.protocol.local", "PerfDataFile", False, "getTempDirectory", "(String)", "credential-username", "Argument[0]", "manual"]
- ["sun.jvmstat.perfdata.monitor.protocol.local", "LocalVmManager", False, "LocalVmManager", "(String)", "", "Argument[0]", "credential-username", "manual"]
- ["sun.jvmstat.perfdata.monitor.protocol.local", "PerfDataFile", False, "getFile", "(String, int)", "", "Argument[0]", "credential-username", "manual"]
- ["sun.jvmstat.perfdata.monitor.protocol.local", "PerfDataFile", False, "getTempDirectory", "(String)", "", "Argument[0]", "credential-username", "manual"]

View File

@@ -3,4 +3,4 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["sun.jvmstat.perfdata.monitor.protocol.rmi", "RemoteVmManager", False, "RemoteVmManager", "(RemoteHost, String)", "credential-username", "Argument[1]", "manual"]
- ["sun.jvmstat.perfdata.monitor.protocol.rmi", "RemoteVmManager", False, "RemoteVmManager", "(RemoteHost, String)", "", "Argument[1]", "credential-username", "manual"]

View File

@@ -3,6 +3,6 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["sun.misc", "Perf", False, "attach", "(String, int, String)", "credential-username", "Argument[0]", "manual"]
- ["sun.misc", "Perf", False, "attach", "(String, int, int)", "credential-username", "Argument[0]", "manual"]
- ["sun.misc", "Perf", False, "attachImpl", "(String, int, int)", "credential-username", "Argument[0]", "manual"]
- ["sun.misc", "Perf", False, "attach", "(String, int, String)", "", "Argument[0]", "credential-username", "manual"]
- ["sun.misc", "Perf", False, "attach", "(String, int, int)", "", "Argument[0]", "credential-username", "manual"]
- ["sun.misc", "Perf", False, "attachImpl", "(String, int, int)", "", "Argument[0]", "credential-username", "manual"]

View File

@@ -3,9 +3,9 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["sun.net.ftp.impl", "FtpClient", False, "login", "(String, char[])", "credential-username", "Argument[0]", "manual"]
- ["sun.net.ftp.impl", "FtpClient", False, "login", "(String, char[], String)", "credential-username", "Argument[0]", "manual"]
- ["sun.net.ftp.impl", "FtpClient", False, "tryLogin", "(String, char[])", "credential-username", "Argument[0]", "manual"]
- ["sun.net.ftp.impl", "FtpClient", False, "login", "(String, char[])", "", "Argument[1]", "credential-password", "manual"]
- ["sun.net.ftp.impl", "FtpClient", False, "login", "(String, char[], String)", "", "Argument[1]", "credential-password", "manual"]
- ["sun.net.ftp.impl", "FtpClient", False, "tryLogin", "(String, char[])", "", "Argument[1]", "credential-password", "manual"]
- ["sun.net.ftp.impl", "FtpClient", False, "login", "(String, char[])", "", "Argument[0]", "credential-username", "manual"]
- ["sun.net.ftp.impl", "FtpClient", False, "login", "(String, char[], String)", "", "Argument[0]", "credential-username", "manual"]
- ["sun.net.ftp.impl", "FtpClient", False, "tryLogin", "(String, char[])", "", "Argument[0]", "credential-username", "manual"]

View File

@@ -3,8 +3,8 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["sun.net.ftp", "FtpClient", False, "login", "(String, char[])", "credential-username", "Argument[0]", "manual"]
- ["sun.net.ftp", "FtpClient", False, "login", "(String, char[], String)", "credential-username", "Argument[0]", "manual"]
- ["sun.net.ftp", "FtpDirEntry", False, "setUser", "(String)", "credential-username", "Argument[0]", "manual"]
- ["sun.net.ftp", "FtpClient", False, "login", "(String, char[])", "", "Argument[1]", "credential-password", "manual"]
- ["sun.net.ftp", "FtpClient", False, "login", "(String, char[], String)", "", "Argument[1]", "credential-password", "manual"]
- ["sun.net.ftp", "FtpClient", False, "login", "(String, char[])", "", "Argument[0]", "credential-username", "manual"]
- ["sun.net.ftp", "FtpClient", False, "login", "(String, char[], String)", "", "Argument[0]", "credential-username", "manual"]
- ["sun.net.ftp", "FtpDirEntry", False, "setUser", "(String)", "", "Argument[0]", "credential-username", "manual"]

View File

@@ -3,6 +3,6 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["sun.net.www.protocol.http", "DigestAuthentication", False, "computeDigest", "(boolean, String, char[], String, String, String, String, String, String)", "credential-username", "Argument[1]", "manual"]
- ["sun.net.www.protocol.http", "DigestAuthentication", False, "computeDigest", "(boolean, String, char[], String, String, String, String, String, String)", "", "Argument[2]", "credential-password", "manual"]
- ["sun.net.www.protocol.http", "DigestAuthentication", False, "encode", "(String, char[], MessageDigest)", "", "Argument[1]", "credential-password", "manual"]
- ["sun.net.www.protocol.http", "DigestAuthentication", False, "computeDigest", "(boolean, String, char[], String, String, String, String, String, String)", "", "Argument[1]", "credential-username", "manual"]

View File

@@ -3,4 +3,4 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["sun.security.acl", "PrincipalImpl", False, "PrincipalImpl", "(String)", "credential-username", "Argument[0]", "manual"]
- ["sun.security.acl", "PrincipalImpl", False, "PrincipalImpl", "(String)", "", "Argument[0]", "credential-username", "manual"]

View File

@@ -3,21 +3,6 @@ extensions:
pack: codeql/java-all
extensible: sinkModel
data:
- ["sun.tools.jconsole", "ConnectDialog", False, "setConnectionParameters", "(String, String, int, String, String, String)", "credential-username", "Argument[3]", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "addHost", "(String, int, String, String)", "credential-username", "Argument[2]", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "addHost", "(String, int, String, String, boolean)", "credential-username", "Argument[2]", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "addUrl", "(String, String, String, boolean)", "credential-username", "Argument[1]", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "failed", "(Exception, String, String, String)", "credential-username", "Argument[2]", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "showConnectDialog", "(String, String, int, String, String, String)", "credential-username", "Argument[3]", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "ProxyClient", "(String, String, String)", "credential-username", "Argument[1]", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "ProxyClient", "(String, int, String, String)", "credential-username", "Argument[2]", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getCacheKey", "(String, String, String)", "credential-username", "Argument[1]", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getCacheKey", "(String, int, String, String)", "credential-username", "Argument[2]", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getConnectionName", "(String, String)", "credential-username", "Argument[1]", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getConnectionName", "(String, int, String)", "credential-username", "Argument[2]", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getProxyClient", "(String, String, String)", "credential-username", "Argument[1]", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getProxyClient", "(String, int, String, String)", "credential-username", "Argument[2]", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "setParameters", "(JMXServiceURL, String, String)", "credential-username", "Argument[1]", "manual"]
- ["sun.tools.jconsole", "ConnectDialog", False, "setConnectionParameters", "(String, String, int, String, String, String)", "", "Argument[4]", "credential-password", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "addHost", "(String, int, String, String)", "", "Argument[3]", "credential-password", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "addHost", "(String, int, String, String, boolean)", "", "Argument[3]", "credential-password", "manual"]
@@ -31,3 +16,18 @@ extensions:
- ["sun.tools.jconsole", "ProxyClient", False, "getProxyClient", "(String, String, String)", "", "Argument[2]", "credential-password", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getProxyClient", "(String, int, String, String)", "", "Argument[3]", "credential-password", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "setParameters", "(JMXServiceURL, String, String)", "", "Argument[2]", "credential-password", "manual"]
- ["sun.tools.jconsole", "ConnectDialog", False, "setConnectionParameters", "(String, String, int, String, String, String)", "", "Argument[3]", "credential-username", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "addHost", "(String, int, String, String)", "", "Argument[2]", "credential-username", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "addHost", "(String, int, String, String, boolean)", "", "Argument[2]", "credential-username", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "addUrl", "(String, String, String, boolean)", "", "Argument[1]", "credential-username", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "failed", "(Exception, String, String, String)", "", "Argument[2]", "credential-username", "manual"]
- ["sun.tools.jconsole", "JConsole", False, "showConnectDialog", "(String, String, int, String, String, String)", "", "Argument[3]", "credential-username", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "ProxyClient", "(String, String, String)", "", "Argument[1]", "credential-username", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "ProxyClient", "(String, int, String, String)", "", "Argument[2]", "credential-username", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getCacheKey", "(String, String, String)", "", "Argument[1]", "credential-username", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getCacheKey", "(String, int, String, String)", "", "Argument[2]", "credential-username", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getConnectionName", "(String, String)", "", "Argument[1]", "credential-username", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getConnectionName", "(String, int, String)", "", "Argument[2]", "credential-username", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getProxyClient", "(String, String, String)", "", "Argument[1]", "credential-username", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "getProxyClient", "(String, int, String, String)", "", "Argument[2]", "credential-username", "manual"]
- ["sun.tools.jconsole", "ProxyClient", False, "setParameters", "(JMXServiceURL, String, String)", "", "Argument[1]", "credential-username", "manual"]