Tony Torralba
|
42b6b26c10
|
Decouple JndiInjection.qll to reuse the taint tracking configuration
|
2021-07-20 15:38:34 +02:00 |
|
Tony Torralba
|
b8ea833a61
|
Merge branch 'main' into atorralba/promote-jndi-injection
|
2021-07-20 15:01:26 +02:00 |
|
Artem Smotrakov
|
158a75e5a1
|
Import UnsafeDeserializationQuery in unsafeDeserialization.ql
|
2021-07-20 10:14:50 +02:00 |
|
Chris Smowton
|
7819d32784
|
Make MediaType stub constants actually constant
This is required to use them in annotations
|
2021-07-19 18:28:30 +01:00 |
|
Chris Smowton
|
a0297d51e5
|
Note fixed test result
the Optional type has now been modelled
|
2021-07-19 18:28:06 +01:00 |
|
Chris Smowton
|
82ea2592ad
|
Spring HTTP: Fix test mistakes
Classes without RestController and methods without GetMapping or similar were never going to be detected.
|
2021-07-19 18:21:13 +01:00 |
|
Chris Smowton
|
392e405f5d
|
Add Spring-XSS test
This covers the cases currently exercised in https://github.com/github/codeql-securitylab/blob/main/java/ql/src/pwntester/security/RestXSS.ql
|
2021-07-19 18:21:11 +01:00 |
|
Chris Smowton
|
16c5952167
|
Add and improve Spring-web stubs
|
2021-07-19 18:20:37 +01:00 |
|
Chris Smowton
|
34a4b71891
|
Add models of JSON-java, aka org.json
|
2021-07-19 17:57:27 +01:00 |
|
Tony Torralba
|
45a72ff6eb
|
Fix InsecureBasicAuth test expectations
|
2021-07-19 13:56:31 +02:00 |
|
Tony Torralba
|
46faf68d64
|
Decouple MvelInjection.qll to reuse the taint tracking configuration
|
2021-07-19 13:50:03 +02:00 |
|
Tony Torralba
|
5ca8b380e9
|
Merge branch 'main' into atorralba/promote-mvel-injection
|
2021-07-19 13:45:10 +02:00 |
|
Artem Smotrakov
|
035f7ac669
|
Refactored libs for unsafe deserialization
|
2021-07-19 13:19:36 +02:00 |
|
Tony Torralba
|
441e8afe81
|
Decouple GrovyInjection.qll to reuse the taint tracking configuration
|
2021-07-19 12:53:37 +02:00 |
|
Tony Torralba
|
b08f417a1e
|
Merge branch 'main' into atorralba/promote-groovy-injection
|
2021-07-19 12:44:03 +02:00 |
|
Artem Smotrakov
|
e02530749b
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-07-19 11:52:12 +02:00 |
|
Anders Schack-Mulligen
|
d1f21a854a
|
Merge pull request #6042 from joefarebrother/spring-http
[Java] Model spring `http` package
|
2021-07-19 11:24:41 +02:00 |
|
Anders Schack-Mulligen
|
c32a75a1b3
|
Merge pull request #6183 from smowton/smowton/feature/javax-json-models
Add models of the jakarta/javax.json package
|
2021-07-19 11:19:21 +02:00 |
|
Artem Smotrakov
|
cfe74b527a
|
Use inline-expectation tests for StaticInitializationVector.ql
|
2021-07-17 01:04:52 +02:00 |
|
Artem Smotrakov
|
218731ca0a
|
Added a query for static initialization vectors in encryption
- Added StaticInitializationVector.ql
- Added StaticInitializationVector.qhelp
- Added tests
|
2021-07-16 19:06:44 +02:00 |
|
Artem Smotrakov
|
3856527d14
|
Refactored tests for unsafe deserialization
|
2021-07-16 18:26:06 +02:00 |
|
Chris Smowton
|
9cde13bf82
|
Note spurious results that stem from weak updates to synthetic fields.
|
2021-07-16 09:44:36 +01:00 |
|
Joe Farebrother
|
f7de2e64c5
|
Fix failing test caused by an imprecission in the stubber
|
2021-07-15 15:15:37 +01:00 |
|
Chris Smowton
|
7b984cc2b0
|
Add models for Apache Commons Lang's Mutable container
|
2021-07-15 14:58:25 +01:00 |
|
Joe Farebrother
|
0e8dd9f335
|
Use generated stubs
|
2021-07-15 11:03:51 +01:00 |
|
Joe Farebrother
|
f3ab295f0f
|
Fix up tests
|
2021-07-15 10:34:21 +01:00 |
|
Joe Farebrother
|
bbc4d4855c
|
Move tests
|
2021-07-15 10:34:18 +01:00 |
|
Joe Farebrother
|
df74a142dd
|
Update for collection flow and add more tests
|
2021-07-15 10:33:33 +01:00 |
|
Joe Farebrother
|
8f89d748fe
|
Add spring tests
|
2021-07-15 10:33:33 +01:00 |
|
Joe Farebrother
|
4be7e94dcc
|
Add more spring stubs
|
2021-07-15 10:33:30 +01:00 |
|
Chris Smowton
|
0b2750828e
|
Add models for org.springframework.jdbc.object
Also add tests for the existing Spring JDBC SQL injection sinks in the process
|
2021-07-14 17:25:00 +01:00 |
|
Sauyon Lee
|
1f97ac88c8
|
Fix tests
|
2021-07-14 05:05:17 -07:00 |
|
Sauyon Lee
|
eaef1c146c
|
Add generated tests
|
2021-07-14 05:05:16 -07:00 |
|
Sauyon Lee
|
16931e5de8
|
Add necessary stubs for Spring
Co-Authored-By: smowton <smowton@github.com>
|
2021-07-14 04:57:56 -07:00 |
|
Anders Schack-Mulligen
|
04244b3c45
|
Merge pull request #5974 from github/sauyon/java/spring-webmultipart
Model Spring `web.multipart`
|
2021-07-14 13:57:24 +02:00 |
|
Anders Schack-Mulligen
|
3c4cd15738
|
Merge pull request #5505 from joefarebrother/android-sql-convert
Java: Convert Android SQL-related flow steps to CSV format
|
2021-07-14 13:56:55 +02:00 |
|
Chris Smowton
|
3ae99b93ca
|
Merge pull request #6215 from aschackmull/java/fix-csv-subtype-interpretation
Java: Fix CSV subtype interpretation
|
2021-07-14 09:57:21 +01:00 |
|
Sauyon Lee
|
51211c0394
|
Add stubs
|
2021-07-13 10:29:02 -07:00 |
|
Sauyon Lee
|
c2c7fee8df
|
Fix tests
|
2021-07-13 10:29:02 -07:00 |
|
Sauyon Lee
|
b01e6d49fb
|
Add generated tests
|
2021-07-13 10:29:01 -07:00 |
|
Anders Schack-Mulligen
|
9388983e41
|
Java: Add missing stub.
|
2021-07-13 15:26:37 +02:00 |
|
Chris Smowton
|
78fe0f810a
|
Add models for decode/encodePointer methods
|
2021-07-13 11:10:46 +01:00 |
|
Chris Smowton
|
cc4401b453
|
Add models of JsonPointer, JsonMergeDiff and JsonPatchBuilder
|
2021-07-12 18:08:45 +01:00 |
|
Chris Smowton
|
6bf931392b
|
Add missing model of JsonObjectBuilder.remove
|
2021-07-12 17:13:39 +01:00 |
|
Artem Smotrakov
|
c98f1a479e
|
Better taint propagation in UnsafeTypeConfig
|
2021-07-09 10:24:15 +02:00 |
|
Artem Smotrakov
|
aefd21075b
|
Added tests for UnsafeDeserialization.ql and Jackson
|
2021-07-09 10:24:10 +02:00 |
|
Joe Farebrother
|
fc017b7934
|
Use ArrayElement of in flow step specifications
|
2021-07-02 14:46:31 +01:00 |
|
Anders Schack-Mulligen
|
3c6604daa7
|
Java: Fix subtypes interpretation.
|
2021-07-02 14:43:56 +02:00 |
|
Anders Schack-Mulligen
|
6813a79423
|
Java: Add test for override of Map.put highlighting problem.
|
2021-07-02 14:41:59 +02:00 |
|
Chris Smowton
|
a51154a8ef
|
Deduplicate Jexl configuration
|
2021-07-02 10:02:28 +01:00 |
|