Tony Torralba
|
99b0624e8b
|
Add change note
|
2023-04-13 10:35:59 +02:00 |
|
Tony Torralba
|
485709a133
|
Fix getCommonSensitiveInfoRegex
|
2023-04-13 10:33:03 +02:00 |
|
Tony Torralba
|
84971c8687
|
Add SensitiveActions tests
|
2023-04-13 10:32:23 +02:00 |
|
Michael Nebel
|
169d8d5cf9
|
Java: All ai-generated models have been manually verified.
|
2023-04-13 09:21:06 +02:00 |
|
Michael Nebel
|
dc8a31f2c5
|
C#/Java: Update dataflow model generator related comments to include provenance.
|
2023-04-13 09:21:06 +02:00 |
|
Michael Nebel
|
de7f486cb1
|
C#/Java: Update model converter queries.
|
2023-04-13 09:21:06 +02:00 |
|
Michael Nebel
|
574f568c26
|
Java: Update model generator expected output.
|
2023-04-13 09:21:06 +02:00 |
|
Michael Nebel
|
df7d58d101
|
Java: Adjust model generator printing to the new provenance.
|
2023-04-13 09:21:06 +02:00 |
|
Michael Nebel
|
6593991c13
|
Java/C#: Update generated models to have provenance df-generated.
|
2023-04-13 09:21:05 +02:00 |
|
Michael Nebel
|
03482e5e59
|
Java/C#: Update the internal documentation.
|
2023-04-13 09:21:05 +02:00 |
|
Michael Nebel
|
54e55e2262
|
Java: Introduce more provenance values.
|
2023-04-13 09:21:04 +02:00 |
|
Michael Nebel
|
efc0650b86
|
Java: Set the provenance default to manual.
|
2023-04-13 09:21:04 +02:00 |
|
Ed Minnix
|
2edad6ec71
|
Remove unused import
|
2023-04-12 20:42:26 -04:00 |
|
Ed Minnix
|
c756bdbc30
|
Fix naming in SensitiveCookieNotHttpOnly
|
2023-04-12 20:39:18 -04:00 |
|
Ed Minnix
|
c49bf01dc8
|
Refactor PermissiveDotRegex.ql
|
2023-04-12 20:37:36 -04:00 |
|
Ed Minnix
|
5164c2480f
|
Refactor SensitiveCookieNotHttpOnly
|
2023-04-12 20:37:36 -04:00 |
|
Ed Minnix
|
8f7d8cbcea
|
Refactor timing attack queries
|
2023-04-12 20:37:36 -04:00 |
|
Ed Minnix
|
597949dbfe
|
Refactor PermissiveDotRegexQuery
|
2023-04-12 20:37:36 -04:00 |
|
Ed Minnix
|
157b7ceaff
|
Refactor TimingAttackAgainstHeader
|
2023-04-12 20:37:36 -04:00 |
|
Ed Minnix
|
a186b771ba
|
Refactor JxBrowserWithoutCertValidation
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
ccdd9bce33
|
Refactor Revocation checking
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
380888e446
|
Refactor ClientSuppliedIpUsedInSecurityCheck
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
3c85ca9740
|
Refactor ThreadResourceAbuse
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
da5a719ffc
|
Refactor UnsafeUsageOfClientSideEncryptionVersion
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
e880a5f187
|
Refactor UnsafeTlsVersion
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
e3f6bc043d
|
Refactor InsecureWebResourceResponse
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
074745315c
|
Refactor SensitiveAndroidFileLeak
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
685a2043a8
|
Refactor UnsafeReflection
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
13e1cc50c8
|
Add SpringUrlRedirect
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
30cfbb83b3
|
Add UncaughtServletException
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
5594e7f6d2
|
Add SensitiveGetQuery
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
478309c90b
|
Add UnsafeDeserializationRmi
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
e2cfea19b5
|
Add UnsafeUrlForward
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
d48adbd175
|
Refactor JsonpInjection
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
8cb5e78832
|
Refactor XXE files
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
4c80ff03de
|
Refactor UnvalidatedCors
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
d254d91f57
|
Refactor Injection queries
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
7002ed5303
|
Refactor InsecureRmiJmxEnvironmentConfiguration
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
6e4e1e52c0
|
Refactor NFEAndroidDoS
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
94768f425f
|
Refactor HashWithoutSalt
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
cb7391177d
|
Refactor MyBatis queries
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
d528c8461f
|
Refactor XQueryInjection.ql
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
e7cbd493d7
|
Refactor FilePathInjection
|
2023-04-12 20:37:35 -04:00 |
|
Ed Minnix
|
47c5db03ab
|
Refactor OpenStream.ql
|
2023-04-12 20:37:34 -04:00 |
|
Ed Minnix
|
5bd9aae072
|
Refactor Log4jJndiInjection.ql
|
2023-04-12 20:37:34 -04:00 |
|
Mathew Payne
|
824ff8ad88
|
Add function signature to model
|
2023-04-12 14:54:06 +00:00 |
|
Mathew Payne
|
ffec22a5d2
|
Add change log notes
|
2023-04-12 14:48:28 +00:00 |
|
Mathew Payne
|
d0529bba2b
|
Add missing models for Java IO
- java.io.OutputStream
- java.nio.file.Files
|
2023-04-12 14:43:11 +00:00 |
|
Chris Smowton
|
7eefa43f5a
|
Rename and document viableArgParamSpecific to make clear it is a temporary hook.
|
2023-04-12 14:33:46 +01:00 |
|
Chris Smowton
|
4d8ca3d759
|
Add dataflow callback to filter out receiver argument flow to Golang interface dispatch candidates.
Other langauges stub the callback.
|
2023-04-12 14:19:06 +01:00 |
|