Jonathan Leitschuh
|
c732cb7759
|
Add HTTP Request Splitting to Netty Query
|
2022-02-09 12:28:10 -05:00 |
|
Jonathan Leitschuh
|
49a73673b6
|
Fix FP from mkdirs call on exact temp directory
|
2022-02-09 11:04:23 -05:00 |
|
Jonathan Leitschuh
|
787e3dac31
|
Update java/ql/src/Security/CWE/CWE-200/TempDirLocalInformationDisclosure.ql
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-09 10:07:56 -05:00 |
|
Tom Hvitved
|
9440a45015
|
Merge branch 'main' into post-release-prep/codeql-cli-2.8.0
|
2022-02-09 09:40:33 +01:00 |
|
luchua-bc
|
4609227e76
|
Use data model for request/session attribute operations
|
2022-02-09 03:24:46 +00:00 |
|
Jonathan Leitschuh
|
7f46640176
|
Consider calls to setReadable(false, false) then setReadable(true, true) to be safe
|
2022-02-08 17:57:10 -05:00 |
|
Chris Smowton
|
a6596ea7ce
|
Fix test requirements, formatting
|
2022-02-08 12:01:32 +00:00 |
|
Benjamin Muskalla
|
b62df5a9ad
|
Merge pull request #7872 from bmuskalla/fixCoverageCollection
Collect framework coverage on demand
|
2022-02-08 11:27:48 +01:00 |
|
Henry Mercer
|
eff0ca01b1
|
Merge pull request #7417 from github/henrymercer/java/update-telemetry-query-metadata
Java: Start running telemetry queries on Code Scanning
|
2022-02-08 10:26:30 +00:00 |
|
Chris Smowton
|
79654592d9
|
Apply suggestions from code review
|
2022-02-08 10:23:46 +00:00 |
|
Benjamin Muskalla
|
ff8a96b96d
|
Rename framework coverage query
Move it to the other summary queries, update all references.
|
2022-02-08 11:14:03 +01:00 |
|
luchua-bc
|
ff4826d203
|
Correct the data model and update qldoc
|
2022-02-08 04:02:27 +00:00 |
|
Jonathan Leitschuh
|
c4112e6d4c
|
Post refactor fixiup
|
2022-02-07 15:02:13 -05:00 |
|
Chris Smowton
|
de38638db6
|
Combine CWE-200 queries
|
2022-02-07 14:22:36 -05:00 |
|
Benjamin Muskalla
|
9af50f5216
|
Turn framework coverage into metric query
|
2022-02-07 12:08:18 +01:00 |
|
github-actions[bot]
|
b4ab86c020
|
Post-release preparation for codeql-cli-2.8.0
|
2022-02-06 23:34:07 +00:00 |
|
Artem Smotrakov
|
f53b2fcc62
|
Updated IgnoredHostnameVerification.ql to cover more uses of HostnameVerifier.verify()
|
2022-02-06 11:23:20 +00:00 |
|
Jonathan Leitschuh
|
1f47ea5164
|
Update to new change note format
|
2022-02-04 17:16:12 -05:00 |
|
Jonathan Leitschuh
|
0268dd9f0a
|
Add file creation sanitizer
|
2022-02-04 17:10:27 -05:00 |
|
Jonathan Leitschuh
|
0a621c2801
|
Fix the formatting in TempDirLocalInformationDisclosureFromMethodCall
|
2022-02-04 17:10:27 -05:00 |
|
Jonathan Leitschuh
|
d5c9af31b2
|
Fixup documentation/code from PR feedback
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
f7a4aac525
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
a4b5573f53
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
a8d25b63ac
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Chris Smowton
|
e795823d97
|
Autoformat TempDirUtils.qll
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
7e514e9ef9
|
Add QLdoc and fix Compiler Errors in Tests
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
cb30385684
|
Update java/ql/src/Security/CWE/CWE-200/TempDirUtils.qll
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
66831989b7
|
Add QLdoc to TempDirUtils
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
7e55c92eb4
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
f6067d28f9
|
Fix file names and formatting from PR feedback
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
41b5011b81
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
7929faedc0
|
Apply suggestions from code review
Co-authored-by: Felicity Chapman <felicitymay@github.com>
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
f910fd4719
|
Remove path flow tracking in 'TempDirLocalInformationDisclosureFromMethodCall'
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
e4c017e888
|
Apply suggestions from code review
Co-authored-by: Arthur Baars <aibaars@github.com>
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
13fed0e9b6
|
Temp Dir Info Disclosure: Final pass and add documentation
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
bc12e994b0
|
Add java.nio.file.Files API checks
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
ecad7534ae
|
Add mkdirs check
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
cf0ed81575
|
Add TempDir taint tracking for Files.write
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
3a15678b1e
|
Java: CWE-200: Temp directory local information disclosure vulnerability
|
2022-02-04 17:10:23 -05:00 |
|
Benjamin Muskalla
|
eee03ebe3b
|
Merge pull request #7767 from bmuskalla/regenerateModelScript
Java: Regenerate framework models automatically
|
2022-02-04 13:29:46 +01:00 |
|
Benjamin Muskalla
|
bc5753cb20
|
Fix path expression
|
2022-02-04 11:43:18 +01:00 |
|
Benjamin Muskalla
|
b747391c74
|
Improve error handling and refactor base path
|
2022-02-04 11:26:19 +01:00 |
|
Tony Torralba
|
4f13bf8941
|
Merge pull request #6492 from atorralba/atorralba/android-cleartext-storage-database
Java: Create new query Cleartext storage of sensitive information in Android databases
|
2022-02-02 16:23:05 +01:00 |
|
github-actions[bot]
|
634134f283
|
Release preparation for version 2.8.0
|
2022-01-27 10:40:20 +00:00 |
|
Benjamin Muskalla
|
c1b5565e4d
|
Automation to regenerate framework models
|
2022-01-27 11:15:10 +01:00 |
|
Andrew Eisenberg
|
a7f755cf12
|
Add new groups for examples packs
Also, remove version numbers. Will make it easier to avoid publishing
the examples packs.
|
2022-01-26 14:49:18 -08:00 |
|
Edoardo Pirovano
|
1b539eb4dc
|
Merge branch rc/3.4 into main
|
2022-01-25 16:22:01 +00:00 |
|
Tony Torralba
|
b59fd4070f
|
Merge pull request #7136 from atorralba/atorralba/promote-insecure-trustmanager
Java: Promote Insecure TrustManager from experimental
|
2022-01-24 14:05:14 +01:00 |
|
luchua-bc
|
27043a09b3
|
File path injection with the JFinal framework
|
2022-01-23 18:07:48 +00:00 |
|
Tony Torralba
|
c5ed5fcaac
|
Apply suggestions from code review
Co-authored-by: Ethan Palm <56270045+ethanpalm@users.noreply.github.com>
|
2022-01-21 16:55:42 +01:00 |
|