Erik Krogh Kristensen
|
101d4358a9
|
detect DOM nodes from event callbacks
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
be9636491b
|
add source for react-hook-form in xss-through-dom
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
65d93c9061
|
detect for DOM elements from DOM events in React
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
458dda9d25
|
add xss-through-dom source from react-final-form
|
2021-02-10 14:17:49 +01:00 |
|
Erik Krogh Kristensen
|
ff3950ce98
|
add model for formik
|
2021-02-10 14:17:49 +01:00 |
|
CodeQL CI
|
653c900d62
|
Merge pull request #4987 from erik-krogh/defensiveFunctions
Approved by esbena
|
2021-02-02 14:47:23 -08:00 |
|
CodeQL CI
|
209fe8d7e5
|
Merge pull request #5049 from erik-krogh/singleQuote
Approved by esbena
|
2021-02-02 13:48:42 -08:00 |
|
CodeQL CI
|
4fdbda3543
|
Merge pull request #5056 from erik-krogh/react
Approved by asgerf
|
2021-02-02 01:40:08 -08:00 |
|
Erik Krogh Kristensen
|
ca435763b0
|
separate message for double and single quotes
|
2021-02-01 23:54:12 +01:00 |
|
Esben Sparre Andreasen
|
9678534f25
|
JS: add tests for some syntactic XSS vector obfuscations
|
2021-02-01 10:20:23 +01:00 |
|
Erik Krogh Kristensen
|
aae69c6537
|
update expected output
|
2021-02-01 09:33:52 +01:00 |
|
Erik Krogh Kristensen
|
c9ec983cd8
|
add js/client-side-unvalidated-url-redirection test for script tags inside react code
|
2021-01-29 12:50:43 +01:00 |
|
Erik Krogh Kristensen
|
39591687ba
|
add js/code-injection sink for script tags in React
|
2021-01-29 12:50:17 +01:00 |
|
Erik Krogh Kristensen
|
3f1e81533c
|
support html attribute concatenations with single quotes
|
2021-01-29 10:37:37 +01:00 |
|
Erik Krogh Kristensen
|
0ba610f7db
|
Merge pull request #5013 from erik-krogh/asmWhitespace
JS: remove benign result for js/whitespace-contradicts-precedence related to " | 0" expressions
|
2021-01-25 13:29:07 +01:00 |
|
Erik Krogh Kristensen
|
d86705fe7a
|
remove benign result for js/whitespace-contradicts-precedence related to " | 0" expressions
|
2021-01-25 10:43:39 +01:00 |
|
CodeQL CI
|
527c41520e
|
Merge pull request #4951 from esbena/js/reintroduce-server-crash
Approved by erik-krogh
|
2021-01-22 06:37:50 -08:00 |
|
CodeQL CI
|
b83c949109
|
Merge pull request #4986 from erik-krogh/logInf
Approved by esbena
|
2021-01-21 06:02:50 -08:00 |
|
Erik Krogh Kristensen
|
a44aefa6c9
|
add test for top-level closure modules - and simplify
|
2021-01-20 19:47:32 +01:00 |
|
Erik Krogh Kristensen
|
bf518f1c90
|
flag less overly general functions with js/unneeded-defensive-code
|
2021-01-20 15:48:12 +01:00 |
|
Erik Krogh Kristensen
|
2e024c3c61
|
fix that type inference assumed every compound-assignment have type number
|
2021-01-20 15:26:39 +01:00 |
|
Erik Krogh Kristensen
|
fbfbe70deb
|
add support for unnamed/default exports in PackageExports.qll
|
2021-01-19 22:40:45 +01:00 |
|
CodeQL CI
|
bdfb81064d
|
Merge pull request #4969 from asgerf/js/angular-dom-santizier-from-core
Approved by erik-krogh
|
2021-01-19 08:45:15 -08:00 |
|
Erik Krogh Kristensen
|
2a8a2832e2
|
Merge pull request #4946 from erik-krogh/libRedos
JS: Add library input as source for `js/polynomial-redos`
|
2021-01-19 17:30:20 +01:00 |
|
Esben Sparre Andreasen
|
3015dcd310
|
JS: reformulate js/server-crash. Support promises and shorter paths.
|
2021-01-19 09:08:52 +01:00 |
|
Erik Krogh Kristensen
|
01900d7ca2
|
remove false positive due to "\n" not being in the relevant relation
|
2021-01-18 14:47:29 +01:00 |
|
CodeQL CI
|
fc2fe6cccb
|
Merge pull request #4928 from esbena/js/rewrite-multi-sanitization
Approved by asgerf
|
2021-01-18 05:11:42 -08:00 |
|
Asger Feldthaus
|
3db6069372
|
JS: Add test for new sink
|
2021-01-18 10:55:34 +00:00 |
|
Asger Feldthaus
|
2752b4ba64
|
JS: Shift line numbers in test
|
2021-01-18 10:54:39 +00:00 |
|
Erik Krogh Kristensen
|
1506ac09e5
|
limit the number of characters produced by getAThreewayIntersect
|
2021-01-15 13:54:16 +01:00 |
|
Erik Krogh Kristensen
|
c5595f4cbd
|
improve alert message for js/polynomial-redos
|
2021-01-14 13:48:26 +01:00 |
|
Erik Krogh Kristensen
|
86e33d9d79
|
select the shortest possible reason
|
2021-01-14 13:38:37 +01:00 |
|
Erik Krogh Kristensen
|
a520a51d42
|
highlight the use of the regular expression, instead of the sink for user input
|
2021-01-14 11:22:20 +01:00 |
|
CodeQL CI
|
4229f556cb
|
Merge pull request #4751 from erik-krogh/logInjection
Approved by asgerf, mchammer01
|
2021-01-14 00:32:46 -08:00 |
|
Esben Sparre Andreasen
|
1bc7d68a50
|
Update javascript/ql/test/query-tests/Security/CWE-730/server-crash.js
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
|
2021-01-13 14:49:42 +01:00 |
|
Erik Krogh Kristensen
|
d71adff079
|
dont sanitize global replacements where the regexp is a char class
|
2021-01-13 10:12:12 +01:00 |
|
Esben Sparre Andreasen
|
d591c519a8
|
JS: reformulate js/server-crash as a path problem
|
2021-01-13 00:08:28 +01:00 |
|
Erik Krogh Kristensen
|
eaee5c2d87
|
add library input as source for js/polynomial-redos
|
2021-01-12 20:21:33 +01:00 |
|
CodeQL CI
|
1c8547c897
|
Merge pull request #4774 from erik-krogh/forms
Approved by asgerf
|
2021-01-12 02:01:38 -08:00 |
|
Esben Sparre Andreasen
|
847687974f
|
JS: only select non-nullable terms in the broken sanitizer
|
2021-01-12 08:50:19 +01:00 |
|
Esben Sparre Andreasen
|
40cfbab335
|
JS: address review feedback
|
2021-01-12 08:49:08 +01:00 |
|
Esben Sparre Andreasen
|
2dbd762bd9
|
JS: reintroduce reverted js/server-crash
This reverts commit 0a8d15ccc4.
|
2021-01-11 14:13:41 +01:00 |
|
Esben Sparre Andreasen
|
580a24e982
|
JS: rewrite js/incomplete-multi-character-sanitization
|
2021-01-11 11:26:45 +01:00 |
|
CodeQL CI
|
807fc94627
|
Merge pull request #4921 from erik-krogh/moreShellSan
Approved by esbena
|
2021-01-08 00:58:26 -08:00 |
|
CodeQL CI
|
c193d9f375
|
Merge pull request #4823 from erik-krogh/furtherReDoS
Approved by esbena
|
2021-01-07 05:24:07 -08:00 |
|
Erik Krogh Kristensen
|
2aa59a3f8b
|
support sanitizers that sanitize individual chars in js/shell-command-constructed-from-input
|
2021-01-07 13:58:25 +01:00 |
|
Erik Krogh Kristensen
|
bfd8d1b1e9
|
Merge branch 'main' into revertSum
|
2021-01-06 23:04:08 +01:00 |
|
CodeQL CI
|
9d4cd0aa85
|
Merge pull request #4862 from erik-krogh/shellSanitizer
Approved by esbena
|
2021-01-06 11:16:12 -08:00 |
|
Erik Krogh Kristensen
|
f1cee70e82
|
add class-field flowstep to js/shell-command-constructed-from-input
|
2021-01-06 14:37:00 +01:00 |
|
Erik Krogh Kristensen
|
3d98732136
|
support nested stars in js/ReDoS
|
2021-01-06 10:37:35 +01:00 |
|