Chris Smowton
|
c17ef42cc7
|
Insecure cookie query: accept ServletRequest.isSecure(), and allow more than one possible input to a setSecure(...) call.
|
2022-05-11 11:59:37 +01:00 |
|
Tony Torralba
|
43b425d0e4
|
Merge pull request #9002 from atorralba/atorralba/https-urls-improvs
Java: Add OkHttp and Retrofit models
|
2022-05-11 10:48:08 +02:00 |
|
Joe Farebrother
|
64227c9109
|
Fix codescanning alerts
|
2022-05-04 15:58:30 +01:00 |
|
Joe Farebrother
|
1605d36ddf
|
Refine polynomial redos sources to exclude length limited methods
|
2022-05-04 15:41:39 +01:00 |
|
Joe Farebrother
|
6794268a3c
|
Split PolynomialRedos definition into a library to avoid duplication in the tests
|
2022-05-04 15:41:38 +01:00 |
|
Joe Farebrother
|
5555985ad6
|
Distingush between whether or not a regex is matched against a full string
Also some fixes and additional tests
|
2022-05-04 15:41:38 +01:00 |
|
Joe Farebrother
|
bb562643c6
|
Support possessive quantifiers, which cannot backtrack.
They are approximated by limiting them to up to one repetition (effectively making *+ like ? and ++ like a no-op).
|
2022-05-04 15:41:37 +01:00 |
|
Joe Farebrother
|
3ce0c2c23b
|
Add more regex use functions in String
|
2022-05-04 15:41:36 +01:00 |
|
Joe Farebrother
|
57ba8a4d1b
|
Improve handling of hex escapes; and support some named character classes
|
2022-05-04 15:41:36 +01:00 |
|
Joe Farebrother
|
5143585080
|
Fix to PolynomialRedos not finding results and to test cases not finding that
|
2022-05-04 15:41:36 +01:00 |
|
Joe Farebrother
|
e23162d91b
|
Add test cases for PolynomialRedos dataflow logic; make fixes
|
2022-05-04 15:41:35 +01:00 |
|
Joe Farebrother
|
5a4316d945
|
Add test cases for exponential redos query
|
2022-05-04 15:41:35 +01:00 |
|
Tony Torralba
|
de8b5f927b
|
Adjust test expectations
|
2022-05-02 16:55:11 +02:00 |
|
Tony Torralba
|
12320aa5d2
|
Fix Intent Redirection sanitizer
|
2022-04-29 12:19:49 +02:00 |
|
Jonathan Leitschuh
|
2565cdb964
|
Add additional File taint value flow models
Adds
- File::getAbsoluteFile
- File::getCanonicalFile
- File::getAbsolutePath
- File::getCanonicalPath
|
2022-04-26 10:42:53 -04:00 |
|
Tony Torralba
|
f1c08bc492
|
Add value-preserving steps for SharedPreferences
|
2022-04-22 17:44:59 +02:00 |
|
Jonathan Leitschuh
|
2753521650
|
Java: Fix Local Temp File/Dir Incorrect Guard Logic
Resolves https://github.com/github/codeql/pull/8032#discussion_r841723906
|
2022-04-06 12:16:09 -04:00 |
|
Chris Smowton
|
9bcf466aa8
|
Accept expected test result improvement
|
2022-03-31 15:19:08 +01:00 |
|
Chris Smowton
|
767453520e
|
Merge pull request #8032 from JLLeitschuh/feat/JLL/check_os
Java: Add Guard Classes for checking OS & unify System Property Access
|
2022-03-18 11:20:36 +00:00 |
|
Joe Farebrother
|
d4b5eed3e4
|
Merge pull request #8410 from joefarebrother/sensitive-logging
Java: Promote Sensitive Logging query
|
2022-03-14 14:50:26 +00:00 |
|
Chris Smowton
|
9f02ca0db2
|
Merge pull request #8357 from p0wn4j/jdbc-url-ssrf-sink
Java: Add JDBC connection SSRF sinks
|
2022-03-14 13:27:34 +00:00 |
|
p0wn4j
|
ee67d27b56
|
Java: Add JDBC connection SSRF sinks
|
2022-03-12 16:35:32 +04:00 |
|
Joe Farebrother
|
06f2c03828
|
Add tests
|
2022-03-11 17:44:52 +00:00 |
|
Erik Krogh Kristensen
|
69353bb014
|
patch upper-case acronyms to be PascalCase
|
2022-03-11 11:10:33 +01:00 |
|
Jonathan Leitschuh
|
5b651f29d8
|
Fix insufficient tests and add documentation
|
2022-03-07 16:39:40 -05:00 |
|
Jonathan Leitschuh
|
dad9a02fbd
|
Update TempDirInfoDisclosure with new OS Guards
|
2022-03-02 12:51:15 -05:00 |
|
Jonathan Leitschuh
|
39828fd596
|
Apply OS guard checks to TempDirLocalInformationDisclosure
|
2022-03-02 12:50:37 -05:00 |
|
Chris Smowton
|
b1c98ae3c2
|
Add further test directly examining signature of method with problematic parameter types
|
2022-02-24 17:39:11 +00:00 |
|
Chris Smowton
|
379f2438a6
|
Add test checking that inheritence is noticed even with annotations present
|
2022-02-24 17:39:11 +00:00 |
|
Jonathan Leitschuh
|
eee521e6ce
|
Fix test failure for TempDirLocalInformationDisclosure
|
2022-02-10 10:40:40 -05:00 |
|
Jonathan Leitschuh
|
49a73673b6
|
Fix FP from mkdirs call on exact temp directory
|
2022-02-09 11:04:23 -05:00 |
|
Jonathan Leitschuh
|
7f46640176
|
Consider calls to setReadable(false, false) then setReadable(true, true) to be safe
|
2022-02-08 17:57:10 -05:00 |
|
Chris Smowton
|
a6596ea7ce
|
Fix test requirements, formatting
|
2022-02-08 12:01:32 +00:00 |
|
Jonathan Leitschuh
|
c4112e6d4c
|
Post refactor fixiup
|
2022-02-07 15:02:13 -05:00 |
|
Chris Smowton
|
de38638db6
|
Combine CWE-200 queries
|
2022-02-07 14:22:36 -05:00 |
|
Jonathan Leitschuh
|
0268dd9f0a
|
Add file creation sanitizer
|
2022-02-04 17:10:27 -05:00 |
|
Jonathan Leitschuh
|
9299c7996d
|
Add information disclosure test fix suggestions
|
2022-02-04 17:10:27 -05:00 |
|
Jonathan Leitschuh
|
79db76dcf8
|
Fix test failures TempDirLocalInformationDisclosureFromSystemProperty
|
2022-02-04 17:10:27 -05:00 |
|
Jonathan Leitschuh
|
7e514e9ef9
|
Add QLdoc and fix Compiler Errors in Tests
|
2022-02-04 17:10:26 -05:00 |
|
Jonathan Leitschuh
|
f910fd4719
|
Remove path flow tracking in 'TempDirLocalInformationDisclosureFromMethodCall'
|
2022-02-04 17:10:25 -05:00 |
|
Jonathan Leitschuh
|
13fed0e9b6
|
Temp Dir Info Disclosure: Final pass and add documentation
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
bc12e994b0
|
Add java.nio.file.Files API checks
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
ecad7534ae
|
Add mkdirs check
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
cf0ed81575
|
Add TempDir taint tracking for Files.write
|
2022-02-04 17:10:24 -05:00 |
|
Jonathan Leitschuh
|
3a15678b1e
|
Java: CWE-200: Temp directory local information disclosure vulnerability
|
2022-02-04 17:10:23 -05:00 |
|
Tony Torralba
|
4f13bf8941
|
Merge pull request #6492 from atorralba/atorralba/android-cleartext-storage-database
Java: Create new query Cleartext storage of sensitive information in Android databases
|
2022-02-02 16:23:05 +01:00 |
|
Tony Torralba
|
b59fd4070f
|
Merge pull request #7136 from atorralba/atorralba/promote-insecure-trustmanager
Java: Promote Insecure TrustManager from experimental
|
2022-01-24 14:05:14 +01:00 |
|
Anders Schack-Mulligen
|
7af6dc7164
|
Merge pull request #7702 from atorralba/atorralba/fix-jndi-injection-sinks
Java: Remove some JNDI Injection sinks
|
2022-01-24 10:53:58 +01:00 |
|
Tony Torralba
|
78d7e538a5
|
Remove some JNDI Injection sinks
Add tests and stubs
|
2022-01-21 17:47:15 +01:00 |
|
Tony Torralba
|
4f253590f1
|
Fix method name in LocalDatabaseOpenMethodAccess
|
2022-01-21 16:55:43 +01:00 |
|