Tony Torralba
|
fb3e56eac8
|
Fix imports and stubs so that tests pass
|
2021-05-06 09:18:48 +02:00 |
|
Tony Torralba
|
a62997463f
|
Remove unused imports; use set literals in hasName
|
2021-05-06 09:18:48 +02:00 |
|
Tony Torralba
|
ed5619498c
|
WIP: XPath Injection promotion
|
2021-05-06 09:18:48 +02:00 |
|
Jonathan Leitschuh
|
67e9f06304
|
[Java] Fix Kryo FP & Kryo 5 Support
Closes #4992
|
2021-05-05 17:38:34 -04:00 |
|
Felicity Chapman
|
8b2009cfb1
|
Minor updates to qhelp file
|
2021-05-05 12:36:29 +01:00 |
|
Tony Torralba
|
6e94dc5b85
|
Autoformatting
|
2021-05-04 13:15:20 +02:00 |
|
Tony Torralba
|
f79d2e06f9
|
Fix failing checks
|
2021-05-04 11:29:09 +02:00 |
|
Anders Schack-Mulligen
|
5bcf810a7c
|
Merge pull request #5821 from JarLob/patch-1
Update UncaughtServletException.qhelp
|
2021-05-04 10:39:02 +02:00 |
|
Anders Schack-Mulligen
|
9ee9186a1a
|
Merge pull request #5825 from github/yo-h/java-diagnostic-queries
Java: split extractor diagnostics query into two
|
2021-05-04 10:12:32 +02:00 |
|
Tony Torralba
|
6b79ca6403
|
Fix warning
|
2021-05-04 09:32:03 +02:00 |
|
luchua-bc
|
703fbf139a
|
Add more methods and update the library name
|
2021-05-04 02:54:49 +00:00 |
|
yo-h
|
edf1a90161
|
Java: split extractor diagnostics query into two
|
2021-05-03 20:27:07 -04:00 |
|
Jonathan Leitschuh
|
dfad1fc740
|
[Java] Add support for com.google.common.base.MoreObjects#firstNonNull
|
2021-05-03 12:58:00 -04:00 |
|
Tony Torralba
|
e68c6e66a5
|
Remove qlref file
|
2021-05-03 17:53:37 +02:00 |
|
Tony Torralba
|
745a6f6fb4
|
Getters called on parameters propagate taint
|
2021-05-03 17:43:33 +02:00 |
|
Jaroslav Lobačevski
|
38bce39baa
|
Update UncaughtServletException.qhelp
There is no single word in https://cwe.mitre.org/data/definitions/600.html about possible DoS or unexpected state.
|
2021-05-03 15:06:57 +03:00 |
|
Tony Torralba
|
4d5ec87de9
|
Use InlineTest
|
2021-05-03 13:27:24 +02:00 |
|
Tony Torralba
|
4bfd34b1fe
|
Moved from experimental
|
2021-05-03 13:15:24 +02:00 |
|
Tony Torralba
|
38e052482c
|
More csv sinks and sources
|
2021-05-03 12:44:53 +02:00 |
|
luchua-bc
|
4709e8139d
|
JPython code injection
|
2021-05-03 01:43:56 +00:00 |
|
Tony Torralba
|
53e04d0d96
|
Refactor to CSV sink model
|
2021-04-30 17:53:43 +02:00 |
|
Chris Smowton
|
b2c0259197
|
Merge pull request #5631 from haby0/UseOfLessTrustedSource
[Java] CWE-348: Using a client-supplied IP address in a security check
|
2021-04-30 15:20:53 +01:00 |
|
haby0
|
fdcc517b9f
|
UseOfLessTrustedSource -> ClientSuppliedIpUsedInSecurityCheck"
|
2021-04-30 17:43:34 +08:00 |
|
haby0
|
f41301f8f5
|
Update java/ql/src/experimental/Security/CWE/CWE-348/UseOfLessTrustedSource.java
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-04-30 16:55:17 +08:00 |
|
haby0
|
0691cac5ab
|
Update java/ql/src/experimental/Security/CWE/CWE-348/UseOfLessTrustedSourceLib.qll
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-04-30 16:54:41 +08:00 |
|
haby0
|
8142810455
|
Update java/ql/src/experimental/Security/CWE/CWE-348/UseOfLessTrustedSource.qhelp
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-04-30 16:54:28 +08:00 |
|
haby0
|
711a74c9c9
|
Eliminate false positives\
|
2021-04-30 10:31:40 +08:00 |
|
intrigus
|
08731fc6cf
|
Fix typo.
|
2021-04-29 20:26:34 +02:00 |
|
Chris Smowton
|
ad9ea40954
|
Merge pull request #5597 from intrigus-lgtm/java/jwt-insecure-parse
[Java] JWT without signature check.
|
2021-04-29 14:41:11 +01:00 |
|
haby0
|
e813257431
|
use hardCode
|
2021-04-29 21:23:52 +08:00 |
|
Anders Schack-Mulligen
|
404a6c1506
|
Merge pull request #5805 from smowton/smowton/admin/spring-setter-method-docs
Document `SpringProperty::getSetterMethod`.
|
2021-04-29 15:10:58 +02:00 |
|
Anders Schack-Mulligen
|
c78285e557
|
Merge pull request #5784 from Marcono1234/marcono1234/switch-expr-stmt-parent
Java: Add StmtParent as superclass of SwitchExpr
|
2021-04-29 15:02:05 +02:00 |
|
Chris Smowton
|
2787c2f874
|
Document SpringProperty::getSetterMethod.
|
2021-04-29 12:28:26 +01:00 |
|
intrigus
|
a8865e2fa2
|
Java: Cleanup jwt stubs.
|
2021-04-28 20:46:09 +02:00 |
|
haby0
|
b0f745365d
|
Node type restriction
|
2021-04-28 14:32:25 +08:00 |
|
edvraa
|
5eb96c1e45
|
Remove Class cast
|
2021-04-27 20:26:29 +03:00 |
|
Tom Hvitved
|
bd0a196a39
|
Java: Update data-flow caching
|
2021-04-27 19:06:39 +02:00 |
|
Tom Hvitved
|
914184f3dd
|
Data flow: Sync files
|
2021-04-27 19:06:39 +02:00 |
|
Tom Hvitved
|
37377644c9
|
Merge pull request #5781 from hvitved/java/predictable-seed-df6
Java: Use separate data-flow copy for `PredictableSeedFlowConfiguration`
|
2021-04-27 19:01:55 +02:00 |
|
Tamás Vajk
|
4cc88662e2
|
Merge pull request #5557 from tamasvajk/feature/java-sinks-csv
Java: convert sinks to CSV
|
2021-04-27 15:58:09 +02:00 |
|
Marcono1234
|
05ce49adaf
|
Java: Add StmtParent as superclass of SwitchExpr
Database type `@stmtparent` already includes `@switchexpr`, this commit merely
changes the class SwitchExpr to also accordingly extend StmtParent.
|
2021-04-27 15:17:55 +02:00 |
|
Tamas Vajk
|
5b79094f34
|
Fix naming in HTTPS URL check
|
2021-04-27 14:59:52 +02:00 |
|
Tamas Vajk
|
e08b629cb5
|
Add documentation for URL opening sinks
|
2021-04-27 10:32:41 +02:00 |
|
Tom Hvitved
|
017beb6786
|
Java: Use separate data-flow copy for PredictableSeedFlowConfiguration
|
2021-04-27 10:07:33 +02:00 |
|
haby0
|
5be9fbbc5a
|
Remove LogOperationSink and PrintSink
|
2021-04-27 14:12:33 +08:00 |
|
Hayk Andriasyan
|
7455b1b4f0
|
Update JSchOSInjectionSanitized.java
|
2021-04-26 15:17:57 +04:00 |
|
p0wn4j
|
3d891f0b39
|
[Java] CWE-078: Add JSch OS command injection sink
|
2021-04-26 18:20:32 +04:00 |
|
intrigus
|
b1a3633495
|
Java: Remove redundant condition + docs.
|
2021-04-23 22:06:04 +02:00 |
|
Chris Smowton
|
455b840712
|
Fix all dead qhelp links
For those documents with no obvious new home I've pointed the links to the Internet Archive.
|
2021-04-23 15:20:21 +01:00 |
|
Anders Schack-Mulligen
|
bc8c55836a
|
Merge pull request #5743 from aschackmull/java/flow-summary-tweaks
Java/C#: Move a couple of flow summary tweaks to the shared implementation.
|
2021-04-23 13:46:04 +02:00 |
|