Jami Cogswell
|
eb1a8e2189
|
Java: update write-file sink kind to file-system-store
|
2023-05-31 15:49:07 -04:00 |
|
Jami Cogswell
|
ac8d985a63
|
Java: update xss sink kind to html-injection and js-injection
|
2023-05-31 15:49:07 -04:00 |
|
Jami Cogswell
|
041caa7405
|
Java: update header-splitting sink kind to response-splitting
|
2023-05-31 15:49:07 -04:00 |
|
Jami Cogswell
|
51df84ed1c
|
Java: update set-hostname-verifier sink kind to hostname-verification
|
2023-05-31 15:49:07 -04:00 |
|
Jami Cogswell
|
b23f384a50
|
Java: update intent-start sink kind to intent-redirection
|
2023-05-31 15:49:07 -04:00 |
|
Jami Cogswell
|
5aa3e57ff3
|
Java: update pending-intent-sent sink kind to pending-intents
|
2023-05-31 15:49:07 -04:00 |
|
Jami Cogswell
|
3ff4c7de8f
|
Java: update ldap sink kind to ldap-injection
|
2023-05-31 15:49:07 -04:00 |
|
Jami Cogswell
|
6d2d25406c
|
Java: update xslt sink kind to xslt-injection
|
2023-05-31 15:49:07 -04:00 |
|
Jami Cogswell
|
cea97b3f2a
|
Java: update mvel sink kind to mvel-injection
|
2023-05-31 15:49:06 -04:00 |
|
Jami Cogswell
|
6cee0c4c75
|
Java: update jexl sink kind to jexl-injection
|
2023-05-31 15:49:06 -04:00 |
|
Jami Cogswell
|
6431d370c1
|
Java: update groovy sink kind to groovy-injection
|
2023-05-31 15:49:06 -04:00 |
|
Jami Cogswell
|
430010daa3
|
Java: update logging sink kind to log-injection
|
2023-05-31 15:49:06 -04:00 |
|
Jami Cogswell
|
8c4b394e1a
|
Java: update ssti sink kind to template-injection
|
2023-05-31 15:49:06 -04:00 |
|
Jami Cogswell
|
fc58d10a4e
|
Java: update xpath sink kind to xpath-injection
|
2023-05-31 15:49:06 -04:00 |
|
Jami Cogswell
|
55be2e5b67
|
Java: update url-redirect sink kind to url-redirection
|
2023-05-31 15:49:06 -04:00 |
|
Jami Cogswell
|
d24d8b1626
|
Java: update sql sink kind to sql-injection
|
2023-05-31 15:49:06 -04:00 |
|
Tony Torralba
|
282ee08ba9
|
Java: Fix GsonDeserializableField
|
2023-05-31 13:26:35 +02:00 |
|
Tony Torralba
|
482bb94ad9
|
Merge pull request #13179 from pwntester/java_gson
[Java] Add basic support for Google's Gson library
|
2023-05-31 11:16:19 +02:00 |
|
Tony Torralba
|
fe26aca238
|
Remove non-ASCII character
|
2023-05-31 09:25:37 +02:00 |
|
Tony Torralba
|
70138448c3
|
Visibility
|
2023-05-30 17:54:59 +02:00 |
|
Tony Torralba
|
54e011188d
|
Formatting
|
2023-05-30 17:50:50 +02:00 |
|
Michael Nebel
|
915042a881
|
Minor cleanup and sync files.
|
2023-05-26 12:25:00 +02:00 |
|
Michael Nebel
|
b7a8660375
|
Java: Re-factor getComponent.
|
2023-05-26 12:24:59 +02:00 |
|
Tony Torralba
|
a276cc3094
|
Convert all command injection sinks to MaD format
|
2023-05-25 11:41:32 +02:00 |
|
Edward Minnix III
|
52340802bb
|
Merge pull request #13097 from egregius313/egregius313/java/webgoat/ssrf-regex-fix
Java: Add constraint to `HostnameSanitizingPrefix` to prevent false negatives in SSRF queries
|
2023-05-23 10:50:43 -04:00 |
|
Tony Torralba
|
6f012d51c0
|
Merge pull request #13091 from atorralba/atorralba/java/inputstreamwrapper-transitive
Java: Make inputStreamWrapper consider supertypes transitively
|
2023-05-23 13:28:17 +02:00 |
|
Ed Minnix
|
43966ebaeb
|
Change regex used in HostnameSanitizingPrefix
|
2023-05-22 15:57:15 -04:00 |
|
Alvaro Muñoz
|
bf3fb09dfd
|
Apply suggestions from code review
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-05-18 12:39:41 +02:00 |
|
Alvaro Muñoz
|
b235b1cbb9
|
improve yaml models
|
2023-05-17 16:40:28 +02:00 |
|
Alvaro Muñoz
|
7baf244ac6
|
remove test predicate
|
2023-05-17 16:18:46 +02:00 |
|
Alvaro Muñoz
|
8cd85a5676
|
add flow support for unmarshaled object fields
|
2023-05-17 16:16:30 +02:00 |
|
Tony Torralba
|
770099f210
|
Merge branch 'main' into atorralba/java/promote-xxe-experimental-sinks
|
2023-05-16 09:49:34 +02:00 |
|
Tony Torralba
|
7d79d87d48
|
Add XPath.evaluate as XXE sink
|
2023-05-15 17:39:35 +02:00 |
|
Tony Torralba
|
549fa7e288
|
Java: make inputStreamWrapper only act on constructors from outside of source
|
2023-05-12 17:47:56 +02:00 |
|
Kasper Svendsen
|
d40cd0f275
|
Java: Make implicit this receivers explicit
|
2023-05-12 12:47:21 +02:00 |
|
Tony Torralba
|
aa14105e1c
|
Don't use the reflexive transitive closure, so that the predicate becomes a little more efficient
|
2023-05-10 16:45:07 +02:00 |
|
Tony Torralba
|
2c41c5b0e2
|
Make inputStreamWrapper consider supertypes transitively
|
2023-05-09 17:27:16 +02:00 |
|
Anders Schack-Mulligen
|
e996eaefb1
|
Merge pull request #13036 from aschackmull/java/typeprefix-perf
Java: Minor perf fix for typePrefixContainsAux1.
|
2023-05-09 08:57:56 +02:00 |
|
Michael Nebel
|
f2f9944a1c
|
Merge pull request #12931 from michaelnebel/neutralkinds
Java/C#: Introduce kind for neutrals.
|
2023-05-09 08:42:38 +02:00 |
|
Edward Minnix III
|
05b1bd881e
|
Merge pull request #12852 from egregius313/egregius313/java/webgoat/model-jwsheader
Java: Model `io.jsonwebtoken.SigningKeyResolverAdapter` and `io.jsonwebtoken.JwsHeader`
|
2023-05-08 10:57:34 -04:00 |
|
Michael Nebel
|
baee4cedfd
|
Apply suggestions from code review
Co-authored-by: Jami <57204504+jcogs33@users.noreply.github.com>
|
2023-05-08 16:19:00 +02:00 |
|
Michael Nebel
|
efa2bd8614
|
Apply suggestions from code review
Co-authored-by: Jami <57204504+jcogs33@users.noreply.github.com>
|
2023-05-08 16:19:00 +02:00 |
|
Michael Nebel
|
bcbda9046f
|
Java: Extend neutrals with a kind column and introduce validation.
|
2023-05-08 16:18:59 +02:00 |
|
Chuan-kai Lin
|
4960305022
|
Merge pull request #13025 from cklin/java-location-tostring-bindingset
Java: Add pragma[only_bind_out] to Top::toString() calls
|
2023-05-08 06:27:42 -07:00 |
|
Mathias Vorreiter Pedersen
|
09ba9a74ce
|
Merge pull request #12959 from MathiasVP/identity-consistency-check
DataFlow: Add an "identity-step" consistency check
|
2023-05-05 10:03:20 +01:00 |
|
Edward Minnix III
|
2d5b35067e
|
Merge pull request #12721 from egregius313/egregius313/java/move-configurations-to-libraries
Java: Move more dataflow configurations to `*Query.qll` files
|
2023-05-04 20:14:22 -04:00 |
|
Edward Minnix III
|
a34a51737f
|
Add SyntheticFields for JwsHeader
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-05-04 16:52:40 -04:00 |
|
Jami
|
3c74c8bbe0
|
Merge pull request #13019 from jcogs33/jcogs33/url-open-stream-updates
Java: switch `url-open-stream` sink models to `experimentalSinkModel`
|
2023-05-04 15:07:44 -04:00 |
|
Chuan-kai Lin
|
d968cee2c4
|
Java: Add pragma[only_bind_out] to Top::toString() calls
|
2023-05-04 11:46:35 -07:00 |
|
Ed Minnix
|
5f3c8fef3f
|
Privacy markers and fixed imports
|
2023-05-04 10:25:17 -04:00 |
|