luchua-bc
|
8c2fddb297
|
Update the condition check and use DataFlow in the ql file
|
2021-10-06 12:17:49 +01:00 |
|
Chris Smowton
|
9e0cf5a2fd
|
Update test expectations to include subpaths
|
2021-10-06 12:17:49 +01:00 |
|
luchua-bc
|
02bfa1ca57
|
Optimize the query
|
2021-10-06 12:16:04 +01:00 |
|
luchua-bc
|
0621e65827
|
Query to detect exposure of sensitive information from android file intent
|
2021-10-06 12:16:04 +01:00 |
|
Tony Torralba
|
0e149f0523
|
Move from experimental
|
2021-10-05 09:18:44 +02:00 |
|
luchua-bc
|
378db7de87
|
Remove local user input and use fluent model
|
2021-09-27 17:33:04 +00:00 |
|
Anders Schack-Mulligen
|
cfa0d46b73
|
Merge pull request #6097 from atorralba/atorralba/promote-xslt-injection
Java: Promote XSLT Injection from experimental
|
2021-09-27 13:14:57 +02:00 |
|
Tony Torralba
|
c792567904
|
Move from experimental
|
2021-09-27 11:57:53 +02:00 |
|
Tony Torralba
|
fc6af0476f
|
Moved from experimental
|
2021-09-27 11:36:48 +02:00 |
|
luchua-bc
|
5264936fc3
|
Correct the run method and add Math.min check
|
2021-09-24 21:00:53 +00:00 |
|
luchua-bc
|
272e4f6cf9
|
Update the query
|
2021-09-24 01:48:11 +00:00 |
|
luchua-bc
|
8170f01b66
|
Query to detect uncontrolled thread resource consumption
|
2021-09-20 02:12:47 +00:00 |
|
Tony Torralba
|
905be67aae
|
Moved from experimental
|
2021-09-15 17:20:27 +02:00 |
|
Chris Smowton
|
29028c5d46
|
Update test expectations to account for dataflow subpaths changes
|
2021-09-10 13:53:41 +01:00 |
|
Chris Smowton
|
2d03840fde
|
Add experimental variants of java/xxe, incorporating new sinks and a version that uses local sources.
Originally authored by @haby0, squashed to clean up a tangled commit history.
|
2021-09-10 13:49:31 +01:00 |
|
Benjamin Muskalla
|
9d5e48430e
|
Merge branch 'main' into charSeqSubSeq
|
2021-09-09 16:04:36 +02:00 |
|
Anders Schack-Mulligen
|
f6541811d2
|
Dataflow: Update more tests.
|
2021-09-07 13:02:20 +02:00 |
|
Benjamin Muskalla
|
190bf90bc8
|
Replace stringbuilder step with model
|
2021-09-01 15:41:16 +02:00 |
|
Benjamin Muskalla
|
d178fe4e5d
|
Fix failing tests
|
2021-09-01 15:41:16 +02:00 |
|
Benjamin Muskalla
|
93bc8aa7b2
|
Fix tests to take trim into account
|
2021-09-01 15:41:15 +02:00 |
|
Chris Smowton
|
7a0555ecb3
|
Merge pull request #6357 from artem-smotrakov/static-iv
Java: Static initialization vector
|
2021-08-26 13:45:43 +01:00 |
|
Fosstars
|
c80a1da483
|
Don't consider copyOf() and clone() in ArrayUpdate
|
2021-08-25 12:11:34 +02:00 |
|
Fosstars
|
4e69081c22
|
Support multi-dimensional arrays
|
2021-08-13 20:52:27 +02:00 |
|
Chris Smowton
|
5ba9347281
|
Merge pull request #6006 from artem-smotrakov/timing-attacks
Java: Timing attacks while comparing results of cryptographic operations
|
2021-08-09 15:30:47 +01:00 |
|
Chris Smowton
|
171dc26531
|
Fix test reference and expectations
|
2021-08-09 13:56:55 +01:00 |
|
Tony Torralba
|
0356ed7f9e
|
Merge pull request #5911 from atorralba/atorralba/promote-missing-jwt-signature-check
Java: Promote Missing JWT signature check query from experimental
|
2021-08-05 09:43:03 +02:00 |
|
Anders Schack-Mulligen
|
6a09a5667d
|
Merge pull request #5931 from atorralba/atorralba/promote-jndi-injection
Java: Promote JNDI Injection query from experimental
|
2021-08-04 15:48:44 +02:00 |
|
Anders Schack-Mulligen
|
7fb1e1578e
|
Merge pull request #5894 from atorralba/atorralba/promote-ognl-injection
Java: Promote OGNL Injection query from experimental
|
2021-08-03 15:31:40 +02:00 |
|
Anders Schack-Mulligen
|
c0d76da1a6
|
Merge pull request #5846 from atorralba/atorralba/promote-unsafe-android-webview-fetch
Java: Promote Unsafe resource loading in Android WebView from experimental
|
2021-08-03 14:24:34 +02:00 |
|
Tony Torralba
|
a33e0bce9d
|
Fix tests affected by Jackson stubs changes
|
2021-08-03 13:15:45 +02:00 |
|
Tony Torralba
|
084cda6daa
|
Merge branch 'main' into atorralba/promote-groovy-injection
|
2021-08-03 09:53:46 +02:00 |
|
Tony Torralba
|
36565802dc
|
Delete unnecesary file
RequestForgery.expected in experimental was an artifact from a merge that wasn't adequately removed
|
2021-08-03 09:48:04 +02:00 |
|
Chris Smowton
|
fad1622730
|
Merge pull request #5435 from haby0/DynamicallyLoadedClasses
Java: CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
|
2021-08-02 16:04:30 +01:00 |
|
Tony Torralba
|
08bdd1aa7a
|
Merge branch 'main' into atorralba/promote-ognl-injection
|
2021-08-02 16:05:38 +02:00 |
|
Anders Schack-Mulligen
|
53e6ddfeb6
|
Merge pull request #6001 from atorralba/atorralba/promote-mvel-injection
Java: Promote MVEL injection query from experimental
|
2021-08-02 14:40:26 +02:00 |
|
Tony Torralba
|
9b384d84cc
|
Merge branch 'main' into atorralba/promote-ognl-injection
|
2021-08-02 14:06:45 +02:00 |
|
Tony Torralba
|
351a24558d
|
Add tests for JacksonSerializability
Upgraded jackson stubs to 2.12
|
2021-08-02 14:03:30 +02:00 |
|
Fosstars
|
44e52517ad
|
Removed unsafeMacCheckWithArraysDeepEquals() test
|
2021-08-01 10:12:38 +02:00 |
|
Fosstars
|
ad54c9d937
|
Two queries for timing attacks
|
2021-08-01 09:47:07 +02:00 |
|
Artem Smotrakov
|
e3b6ceade5
|
Renamed NonConstantTimeCryptoComparison.ql to NonConstantTimeCheckOnSignature.ql
|
2021-08-01 09:47:06 +02:00 |
|
Artem Smotrakov
|
8b557765b3
|
Narrow NonConstantTimeCryptoComparison.ql to timing attack on signatures and MACs only
|
2021-08-01 09:47:06 +02:00 |
|
Artem Smotrakov
|
1f2a9cdda7
|
Added taint propagation steps for hashes in NonConstantTimeCryptoComparison.ql
|
2021-08-01 09:47:06 +02:00 |
|
Artem Smotrakov
|
c96d939cf5
|
Covered custom fast-fail checks in NonConstantTimeCryptoComparison.ql
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
|
2021-08-01 09:47:06 +02:00 |
|
Artem Smotrakov
|
8c4da16459
|
More test cases for java/non-constant-time-crypto-comparison
|
2021-08-01 09:47:04 +02:00 |
|
Artem Smotrakov
|
a4f3a5a88e
|
Take into account remote user input in java/non-constant-time-crypto-comparison
|
2021-08-01 09:47:03 +02:00 |
|
Artem Smotrakov
|
8e6d227dc0
|
More sinks for java/ql/src/experimental/Security/CWE/CWE-208/NonConstantTimeCryptoComparison.ql
|
2021-08-01 09:47:03 +02:00 |
|
Artem Smotrakov
|
dfa3b523d0
|
Renamed files
|
2021-08-01 09:47:03 +02:00 |
|
Artem Smotrakov
|
75f67959f3
|
Covered Arrays.deepEquals() in NonConstantTimeCryptoComparison.ql
|
2021-08-01 09:47:02 +02:00 |
|
Artem Smotrakov
|
5dbcf1d611
|
Covered Object.deepEquals() in NotConstantTimeCryptoComparison.ql
|
2021-08-01 09:47:02 +02:00 |
|
Artem Smotrakov
|
f245dc3ac8
|
Removed hashes from NotConstantTimeCryptoComparison.ql
|
2021-08-01 09:47:02 +02:00 |
|