Joe Farebrother
|
9dc28eb9b5
|
Merge pull request #6387 from joefarebrother/guava-cache
Java: Model guava cache package
|
2021-08-19 10:53:48 +01:00 |
|
Chris Smowton
|
48818ebd6d
|
Merge pull request #6434 from smowton/smowton/admin/jodd-unsafe-deserialization
Java: Unsafe deserialization: add support for Jodd JSON library
|
2021-08-18 17:26:02 +01:00 |
|
Sauyon Lee
|
fd0ea15719
|
Add stubs for Spring web.util tests
|
2021-08-12 11:20:48 -07:00 |
|
Owen Mansel-Chan
|
51a7018afc
|
Add stubs
|
2021-08-06 07:06:16 +01:00 |
|
Chris Smowton
|
0b6c991ac4
|
Unsafe deserialization: add support for Jodd JSON library
|
2021-08-05 16:01:14 +01:00 |
|
Tony Torralba
|
0356ed7f9e
|
Merge pull request #5911 from atorralba/atorralba/promote-missing-jwt-signature-check
Java: Promote Missing JWT signature check query from experimental
|
2021-08-05 09:43:03 +02:00 |
|
Anders Schack-Mulligen
|
1932f604dc
|
Merge pull request #6419 from smowton/smowton/admin/unsafe-deserialization-jabsorb
Add unsafe-deserialization support for Jabsorb
|
2021-08-05 09:04:23 +02:00 |
|
Chris Smowton
|
69549e9ce3
|
Add unsafe-deserialization support for Jabsorb
This is partly extracted from https://github.com/github/codeql/pull/5954
|
2021-08-04 15:35:50 +01:00 |
|
Anders Schack-Mulligen
|
6a09a5667d
|
Merge pull request #5931 from atorralba/atorralba/promote-jndi-injection
Java: Promote JNDI Injection query from experimental
|
2021-08-04 15:48:44 +02:00 |
|
Anders Schack-Mulligen
|
7fb1e1578e
|
Merge pull request #5894 from atorralba/atorralba/promote-ognl-injection
Java: Promote OGNL Injection query from experimental
|
2021-08-03 15:31:40 +02:00 |
|
Anders Schack-Mulligen
|
c0d76da1a6
|
Merge pull request #5846 from atorralba/atorralba/promote-unsafe-android-webview-fetch
Java: Promote Unsafe resource loading in Android WebView from experimental
|
2021-08-03 14:24:34 +02:00 |
|
Tony Torralba
|
f5cbec4938
|
Fix tests affected by Jackson stubs changes
|
2021-08-03 14:22:55 +02:00 |
|
Anders Schack-Mulligen
|
fb9feabe64
|
Merge pull request #6062 from atorralba/atorralba/promote-groovy-injection
Java: Promote Groovy Code Injection from experimental
|
2021-08-03 14:19:15 +02:00 |
|
Chris Smowton
|
f83f950be6
|
Merge pull request #6325 from smowton/smowton/feature/org-json-models
Java: add models of JSON-java, aka `org.json`
|
2021-08-03 10:33:49 +01:00 |
|
Tony Torralba
|
084cda6daa
|
Merge branch 'main' into atorralba/promote-groovy-injection
|
2021-08-03 09:53:46 +02:00 |
|
Chris Smowton
|
fad1622730
|
Merge pull request #5435 from haby0/DynamicallyLoadedClasses
Java: CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
|
2021-08-02 16:04:30 +01:00 |
|
Tony Torralba
|
08bdd1aa7a
|
Merge branch 'main' into atorralba/promote-ognl-injection
|
2021-08-02 16:05:38 +02:00 |
|
Anders Schack-Mulligen
|
53e6ddfeb6
|
Merge pull request #6001 from atorralba/atorralba/promote-mvel-injection
Java: Promote MVEL injection query from experimental
|
2021-08-02 14:40:26 +02:00 |
|
Tony Torralba
|
f4b78ef3bd
|
Fix stubs
|
2021-08-02 14:12:05 +02:00 |
|
Tony Torralba
|
9b384d84cc
|
Merge branch 'main' into atorralba/promote-ognl-injection
|
2021-08-02 14:06:45 +02:00 |
|
Tony Torralba
|
351a24558d
|
Add tests for JacksonSerializability
Upgraded jackson stubs to 2.12
|
2021-08-02 14:03:30 +02:00 |
|
Anders Schack-Mulligen
|
3b676d432f
|
Merge pull request #5900 from artem-smotrakov/unsafe-jackson-deserialization
Java: Unsafe deserialization with Jackson
|
2021-08-02 12:45:30 +02:00 |
|
Fosstars
|
a4b0041120
|
Better looksLikeResolveClassStep() predicate
|
2021-07-30 09:28:03 +02:00 |
|
Joe Farebrother
|
f1ca29a846
|
Add more stubs
|
2021-07-29 15:58:42 +01:00 |
|
Joe Farebrother
|
096509b9aa
|
Generate tests and stubs
|
2021-07-29 15:01:50 +01:00 |
|
Artem Smotrakov
|
7fec575df8
|
Simplify JsonTypeInfo stub
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-07-28 14:23:50 +02:00 |
|
haby0
|
2a50cf8244
|
Fix
|
2021-07-22 22:24:09 +08:00 |
|
haby0
|
d8f5f6987b
|
Fix
|
2021-07-22 21:53:41 +08:00 |
|
haby0
|
e160352b38
|
Fix
|
2021-07-22 21:48:46 +08:00 |
|
haby0
|
4ebf0ed7c5
|
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
|
2021-07-22 21:45:29 +08:00 |
|
Tony Torralba
|
99e66cffa2
|
Merge branch 'main' into atorralba/promote-unsafe-android-webview-fetch
|
2021-07-20 17:30:56 +02:00 |
|
Tony Torralba
|
b6904a7992
|
Merge branch 'main' into atorralba/promote-ognl-injection
|
2021-07-20 17:17:17 +02:00 |
|
Tony Torralba
|
430d9f1834
|
Merge branch 'main' into atorralba/promote-missing-jwt-signature-check
|
2021-07-20 16:20:35 +02:00 |
|
Tony Torralba
|
b8ea833a61
|
Merge branch 'main' into atorralba/promote-jndi-injection
|
2021-07-20 15:01:26 +02:00 |
|
Chris Smowton
|
7819d32784
|
Make MediaType stub constants actually constant
This is required to use them in annotations
|
2021-07-19 18:28:30 +01:00 |
|
Chris Smowton
|
16c5952167
|
Add and improve Spring-web stubs
|
2021-07-19 18:20:37 +01:00 |
|
Chris Smowton
|
34a4b71891
|
Add models of JSON-java, aka org.json
|
2021-07-19 17:57:27 +01:00 |
|
Tony Torralba
|
5ca8b380e9
|
Merge branch 'main' into atorralba/promote-mvel-injection
|
2021-07-19 13:45:10 +02:00 |
|
Tony Torralba
|
b08f417a1e
|
Merge branch 'main' into atorralba/promote-groovy-injection
|
2021-07-19 12:44:03 +02:00 |
|
Anders Schack-Mulligen
|
d1f21a854a
|
Merge pull request #6042 from joefarebrother/spring-http
[Java] Model spring `http` package
|
2021-07-19 11:24:41 +02:00 |
|
Anders Schack-Mulligen
|
c32a75a1b3
|
Merge pull request #6183 from smowton/smowton/feature/javax-json-models
Add models of the jakarta/javax.json package
|
2021-07-19 11:19:21 +02:00 |
|
Joe Farebrother
|
f7de2e64c5
|
Fix failing test caused by an imprecission in the stubber
|
2021-07-15 15:15:37 +01:00 |
|
Chris Smowton
|
7b984cc2b0
|
Add models for Apache Commons Lang's Mutable container
|
2021-07-15 14:58:25 +01:00 |
|
Joe Farebrother
|
0e8dd9f335
|
Use generated stubs
|
2021-07-15 11:03:51 +01:00 |
|
Joe Farebrother
|
4be7e94dcc
|
Add more spring stubs
|
2021-07-15 10:33:30 +01:00 |
|
Chris Smowton
|
0b2750828e
|
Add models for org.springframework.jdbc.object
Also add tests for the existing Spring JDBC SQL injection sinks in the process
|
2021-07-14 17:25:00 +01:00 |
|
Sauyon Lee
|
16931e5de8
|
Add necessary stubs for Spring
Co-Authored-By: smowton <smowton@github.com>
|
2021-07-14 04:57:56 -07:00 |
|
Anders Schack-Mulligen
|
04244b3c45
|
Merge pull request #5974 from github/sauyon/java/spring-webmultipart
Model Spring `web.multipart`
|
2021-07-14 13:57:24 +02:00 |
|
Sauyon Lee
|
51211c0394
|
Add stubs
|
2021-07-13 10:29:02 -07:00 |
|
Anders Schack-Mulligen
|
9388983e41
|
Java: Add missing stub.
|
2021-07-13 15:26:37 +02:00 |
|