Chris Smowton
|
7509e36382
|
Remove no-longer-needed BasicRequestLine model from InsecureBasicAuth.ql; adjust test expectations accordingly
|
2021-06-17 11:43:33 +01:00 |
|
Chris Smowton
|
487c1db6ed
|
Promote SSRF query to main query set
|
2021-06-17 11:41:01 +01:00 |
|
Anders Schack-Mulligen
|
8fe2f4a554
|
Merge pull request #6034 from owen-mc/java/jax-rs
Improve JAX-WS and JAX-RS models
|
2021-06-17 12:35:34 +02:00 |
|
Tony Torralba
|
47fffb04a6
|
Merge branch 'main' into atorralba/promote-ognl-injection
|
2021-06-16 15:46:33 +02:00 |
|
Tony Torralba
|
91ba30a781
|
Merge branch 'main' into atorralba/promote-missing-jwt-signature-check
|
2021-06-16 15:46:14 +02:00 |
|
Tony Torralba
|
dab33b21fb
|
Merge branch 'main' into atorralba/promote-mvel-injection
|
2021-06-16 15:44:43 +02:00 |
|
Tony Torralba
|
bf2be6ec7c
|
Merge branch 'main' into atorralba/promote-jndi-injection
|
2021-06-16 15:34:37 +02:00 |
|
Tony Torralba
|
66d49aa4e8
|
Fix InsecureBasicAuth tests affected by the new URL summary
|
2021-06-16 13:01:40 +02:00 |
|
Tony Torralba
|
357b0e1a90
|
Fix SSRF tests affected by the new URL summary
|
2021-06-16 13:01:40 +02:00 |
|
Tony Torralba
|
356601ce15
|
Moved from experimental
|
2021-06-16 13:01:38 +02:00 |
|
Chris Smowton
|
76838809bb
|
Merge pull request #5818 from artem-smotrakov/rmi-deserialization
Java: Unsafe RMI deserialization
|
2021-06-11 13:43:07 +01:00 |
|
Owen Mansel-Chan
|
e0130a932e
|
Update experimental query using NewCookie
|
2021-06-10 13:33:20 +01:00 |
|
Owen Mansel-Chan
|
ee6019a2d8
|
Fix tests for experimental httponly query
|
2021-06-10 13:31:28 +01:00 |
|
Anders Schack-Mulligen
|
96da85449d
|
Merge pull request #5823 from atorralba/promote-jexl-injection
Java: Promote JEXL Injection query from experimental
|
2021-06-07 10:03:12 +02:00 |
|
Chris Smowton
|
4ddf4558a7
|
Merged simplified query
|
2021-06-04 16:07:15 +02:00 |
|
Tony Torralba
|
56a429a5f9
|
Merge branch 'main' into promote-jexl-injection
|
2021-06-03 11:10:56 +02:00 |
|
Tony Torralba
|
59e6e1ffac
|
Moved from experimental
|
2021-06-02 09:58:30 +02:00 |
|
Anders Schack-Mulligen
|
43d1b0ab27
|
Java: Update qltests.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
a4661e1aca
|
Merge pull request #5704 from edvraa/regexj
Java: Regex injection
|
2021-06-01 11:45:59 +02:00 |
|
Timo Mueller
|
75f6ec1f0d
|
Updated test cases to include test for java10+ CREDENTIALS_FILTER_PATTERN constant
|
2021-05-25 17:08:58 +02:00 |
|
Timo Mueller
|
59ebe08c78
|
Added stup for RMIConnectorServer for valid test case
|
2021-05-25 16:40:41 +02:00 |
|
Artem Smotrakov
|
c837605c85
|
Added test cases with sanitizers for UnsafeDeserializationRmi.ql
|
2021-05-23 13:01:22 +02:00 |
|
Artem Smotrakov
|
d2e29fc72c
|
Renamed RmiUnsafeDeserialization.ql -> UnsafeDeserializationRmi.ql
|
2021-05-23 10:21:05 +02:00 |
|
Artem Smotrakov
|
e28f919f3d
|
Look for remote callable method only in RmiUnsafeDeserialization.ql
|
2021-05-23 10:21:05 +02:00 |
|
Artem Smotrakov
|
5ffe04d6a5
|
Updated expected output for RmiUnsafeDeserialization.java test
|
2021-05-23 10:21:04 +02:00 |
|
Artem Smotrakov
|
3d20330a92
|
More tests for RmiUnsafeDeserialization
|
2021-05-23 10:21:04 +02:00 |
|
Artem Smotrakov
|
ec6186a1c5
|
Draft of tests for RmiUnsafeDeserialization.ql
|
2021-05-23 10:21:04 +02:00 |
|
Tony Torralba
|
1351516e9a
|
Moved JNDI injection related files from experimental to standard
|
2021-05-19 11:32:51 +02:00 |
|
Tony Torralba
|
e58746508d
|
Merge branch 'main' into atorralba/promote-ognl-injection
|
2021-05-19 10:41:08 +02:00 |
|
luchua-bc
|
e4699f7fa9
|
Optimize the query
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
d664aa6d6a
|
Include more scenarios and update qldoc
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
852bcfb5c7
|
Refactor the ScriptEngine query and the Rhino code injection query into one
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
b0b5338359
|
Rhino code injection
|
2021-05-18 16:12:22 +00:00 |
|
Chris Smowton
|
4230869ee2
|
Merge pull request #5819 from luchua-bc/java/jpython-injection
Java: CWE-094 Jython code injection
|
2021-05-18 16:38:40 +01:00 |
|
Chris Smowton
|
71f540a755
|
Merge pull request #5844 from haby0/SpringRedirects
[Java] CWE-601 Spring url redirection detect
|
2021-05-18 16:37:40 +01:00 |
|
haby0
|
a0cd551bae
|
Add filtering of String.format
|
2021-05-18 11:05:10 +08:00 |
|
Tony Torralba
|
3e4ccaf9a8
|
Move from experimental to standard
|
2021-05-17 10:41:54 +02:00 |
|
haby0
|
498c99e26c
|
Add left value, Add return expression tracing flow
|
2021-05-14 16:31:59 +08:00 |
|
haby0
|
effa2b162a
|
Add spring url redirection detect
|
2021-05-13 09:55:37 +08:00 |
|
luchua-bc
|
e7cd6c9972
|
Optimize the query
|
2021-05-11 16:56:12 +00:00 |
|
Tony Torralba
|
fc03b92e11
|
Moved from experimental to standard
|
2021-05-11 15:42:13 +02:00 |
|
Chris Smowton
|
0afe22d60c
|
Merge pull request #5710 from p0wn4j/jsch-os-injection
[Java] CWE-078: Add JSch lib OS Command Injection sink
|
2021-05-10 16:12:00 +01:00 |
|
Tony Torralba
|
d99b5bfc66
|
Reuse previous tests from experimental
|
2021-05-10 11:17:20 +02:00 |
|
Tony Torralba
|
e78e5b9ee4
|
Merge branch 'main' into promote-jexl-injection
|
2021-05-07 12:36:49 +02:00 |
|
Timo Mueller
|
787a4ede85
|
Fixed file reference in test cases
|
2021-05-04 15:33:53 +02:00 |
|
Timo Mueller
|
374ed851a0
|
Fixed file reference in test cases
|
2021-05-04 15:12:50 +02:00 |
|
luchua-bc
|
703fbf139a
|
Add more methods and update the library name
|
2021-05-04 02:54:49 +00:00 |
|
Tony Torralba
|
4bfd34b1fe
|
Moved from experimental
|
2021-05-03 13:15:24 +02:00 |
|
Tony Torralba
|
38e052482c
|
More csv sinks and sources
|
2021-05-03 12:44:53 +02:00 |
|
luchua-bc
|
4709e8139d
|
JPython code injection
|
2021-05-03 01:43:56 +00:00 |
|