Tony Torralba
|
7dbdba28cc
|
Consider search methods with unsafe SearchControls
|
2021-05-21 15:21:04 +02:00 |
|
Anders Schack-Mulligen
|
d00618f4f4
|
Java: Improve performance of virtual dispatch calculation.
|
2021-05-21 15:04:08 +02:00 |
|
Sebastian Bauersfeld
|
ffcca4d5e9
|
Add change note.
|
2021-05-20 20:07:14 +07:00 |
|
Sebastian Bauersfeld
|
28f597440f
|
Add method invocations of Spring's SavedRequest as a remote sources.
|
2021-05-20 20:00:14 +07:00 |
|
Tony Torralba
|
2613e58916
|
Remove duplicated class
|
2021-05-20 12:49:02 +02:00 |
|
Tony Torralba
|
0589dd7e54
|
Move Jndi.qll from experimental
|
2021-05-20 12:30:28 +02:00 |
|
Tony Torralba
|
0c1fe9be4f
|
Add change note
|
2021-05-20 12:00:11 +02:00 |
|
Tony Torralba
|
c1e71b60b4
|
Use InlineExpectationsTest
|
2021-05-20 12:00:11 +02:00 |
|
Tony Torralba
|
3f0b803796
|
Refactored to use CSV sink models
|
2021-05-20 12:00:05 +02:00 |
|
Anders Schack-Mulligen
|
4406b8e339
|
Dataflow: Sync.
|
2021-05-19 19:22:36 +02:00 |
|
Anders Schack-Mulligen
|
bb258813a1
|
Dataflow: Improve performance for dispatch-join in flow-through.
|
2021-05-19 19:20:57 +02:00 |
|
Tony Torralba
|
1351516e9a
|
Moved JNDI injection related files from experimental to standard
|
2021-05-19 11:32:51 +02:00 |
|
Tony Torralba
|
43d4575359
|
Add createParser as taint preserving callable
|
2021-05-19 11:20:54 +02:00 |
|
Tony Torralba
|
e58746508d
|
Merge branch 'main' into atorralba/promote-ognl-injection
|
2021-05-19 10:41:08 +02:00 |
|
luchua-bc
|
02aa9c6fc7
|
Optimize the sink and update qldoc
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
d4323a4a54
|
Update qldoc
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
9d392263a5
|
Refactor inconsistent method names
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
2fa249a8eb
|
Update method name and qldoc
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
2c1374bdcf
|
Use inline implementation for ScriptEngineFactory
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
0ac8453398
|
Allow all arguments of methods in ScriptEngineFactory
|
2021-05-18 16:12:23 +00:00 |
|
luchua-bc
|
e4699f7fa9
|
Optimize the query
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
d664aa6d6a
|
Include more scenarios and update qldoc
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
852bcfb5c7
|
Refactor the ScriptEngine query and the Rhino code injection query into one
|
2021-05-18 16:12:22 +00:00 |
|
luchua-bc
|
b0b5338359
|
Rhino code injection
|
2021-05-18 16:12:22 +00:00 |
|
Chris Smowton
|
4230869ee2
|
Merge pull request #5819 from luchua-bc/java/jpython-injection
Java: CWE-094 Jython code injection
|
2021-05-18 16:38:40 +01:00 |
|
Chris Smowton
|
71f540a755
|
Merge pull request #5844 from haby0/SpringRedirects
[Java] CWE-601 Spring url redirection detect
|
2021-05-18 16:37:40 +01:00 |
|
luchua-bc
|
2a0721b2ae
|
Optimize the sink and update method name
|
2021-05-18 12:18:14 +00:00 |
|
haby0
|
e46de44473
|
Solve errors caused by private ownership
|
2021-05-18 19:56:32 +08:00 |
|
haby0
|
caf5f4d605
|
modified comment
|
2021-05-18 19:10:03 +08:00 |
|
Tony Torralba
|
34a55e77ef
|
Add missing subtype test
|
2021-05-18 09:38:35 +02:00 |
|
Anders Schack-Mulligen
|
9b0e3b1950
|
Merge pull request #5814 from JLLeitschuh/feat/JLL/jackson_as_taint_step
[Java] Add taint tracking through Jackson deserialization
|
2021-05-18 09:31:16 +02:00 |
|
haby0
|
a0cd551bae
|
Add filtering of String.format
|
2021-05-18 11:05:10 +08:00 |
|
luchua-bc
|
e652d8771c
|
Update method name and qldoc
|
2021-05-17 20:36:15 +00:00 |
|
Chris Smowton
|
ef410b9984
|
Update java/change-notes/2021-05-14-close-resource-leaks-improvements.md
|
2021-05-17 19:27:10 +01:00 |
|
Tony Torralba
|
347bd2ebc2
|
Added change note
|
2021-05-17 17:51:07 +02:00 |
|
Tony Torralba
|
1815656a02
|
Use set literals for OGNL packages
|
2021-05-17 16:56:37 +02:00 |
|
Tony Torralba
|
8d682000b4
|
Fix QLDocs
|
2021-05-17 16:53:30 +02:00 |
|
Tony Torralba
|
ed13c17ea8
|
Fix qhelp file
|
2021-05-17 16:52:08 +02:00 |
|
Tony Torralba
|
bc2370ae1d
|
Use InlineExpectationsTest for tests
|
2021-05-17 15:58:33 +02:00 |
|
Tony Torralba
|
cfb38c43b3
|
QLDocs
|
2021-05-17 15:04:50 +02:00 |
|
Tony Torralba
|
897cd5384f
|
Created JWT.qll and refactored to use CSV models
|
2021-05-17 14:44:33 +02:00 |
|
luchua-bc
|
7af1984348
|
Update the change note
|
2021-05-17 11:35:35 +00:00 |
|
haby0
|
689c28a178
|
modified JsonIoSafeOptionalArgs
|
2021-05-17 19:00:59 +08:00 |
|
haby0
|
95c33a240f
|
Update java/change-notes/2021-05-17-add-unsafe-deserialization-sinks.md
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-05-17 18:49:16 +08:00 |
|
Tony Torralba
|
3e4ccaf9a8
|
Move from experimental to standard
|
2021-05-17 10:41:54 +02:00 |
|
Anders Schack-Mulligen
|
77c93dcf26
|
Make private
|
2021-05-17 10:35:04 +02:00 |
|
haby0
|
58d774ae85
|
add change notes
|
2021-05-17 14:52:05 +08:00 |
|
luchua-bc
|
1a072f3bb9
|
Move APIs from predicates flagged auto-generated to the other section
|
2021-05-14 20:38:23 +00:00 |
|
Marcono1234
|
e205e4bbce
|
Java: Add change note for close resource query changes
|
2021-05-14 22:31:14 +02:00 |
|
Marcono1234
|
73c7e15580
|
Java: Add back StringInputStream to CloseReader.ql
|
2021-05-14 22:25:00 +02:00 |
|