Erik Krogh Kristensen
|
fc7e9eb8c8
|
add test for non-tracked aliasing
|
2020-05-18 22:40:41 +02:00 |
|
Max Schaefer
|
6797fec1a3
|
JavaScript: Add more models of packages that execute commands over SSH.
|
2020-05-18 12:08:14 +01:00 |
|
Esben Sparre Andreasen
|
a9ba6ac659
|
JS: make LocalObjects::isEscape aware of yield
|
2020-05-18 12:43:46 +02:00 |
|
semmle-qlci
|
14664be467
|
Merge pull request #3468 from p0/imp/nodejs-vm-sinks
Approved by esbena
|
2020-05-18 11:10:13 +01:00 |
|
Esben Sparre Andreasen
|
b3691cd0e9
|
JS: change MembershipTest to MembershipCandidate
|
2020-05-18 11:51:00 +02:00 |
|
Esben Sparre Andreasen
|
ddb545c182
|
JS: introduce MembershipTests.qll and use in two locations
|
2020-05-18 09:50:00 +02:00 |
|
semmle-qlci
|
0230b79efc
|
Merge pull request #3391 from erik-krogh/SplitFPs
Approved by esbena
|
2020-05-18 08:46:26 +01:00 |
|
Erik Krogh Kristensen
|
c8cf958c8a
|
add test cases for js/shell-command-constructed-from-input
|
2020-05-17 10:32:27 +02:00 |
|
Erik Krogh Kristensen
|
a1a6826278
|
support non-SourceNode in IndirectCommandArgument#argumentList
|
2020-05-16 23:15:37 +02:00 |
|
semmle-qlci
|
8d41ce1630
|
Merge pull request #3480 from erik-krogh/moreSlip
Approved by esbena
|
2020-05-16 21:17:27 +01:00 |
|
semmle-qlci
|
a536069059
|
Merge pull request #3408 from esbena/js/unsafe-html-expansion
Approved by asgerf, mchammer01
|
2020-05-15 08:24:12 +01:00 |
|
Erik Krogh Kristensen
|
e7d1b12ac8
|
add test
|
2020-05-14 20:31:23 +02:00 |
|
Pavel Avgustinov
|
ab2d059ed4
|
JavaScript: Model extra sinks in vm module
|
2020-05-14 10:01:40 +01:00 |
|
Erik Krogh Kristensen
|
b12e21edcc
|
add test for new zipslip sanitizer
|
2020-05-14 10:11:37 +02:00 |
|
Erik Krogh Kristensen
|
4175d36269
|
add test case
|
2020-05-14 09:46:54 +02:00 |
|
Esben Sparre Andreasen
|
7722d77c86
|
JS: add the NoSQL $where as a sink for js/code-injection
|
2020-05-13 08:30:22 +02:00 |
|
Esben Sparre Andreasen
|
20cf04442c
|
JS: model marsdb and minimongo
|
2020-05-13 08:28:59 +02:00 |
|
Erik Krogh Kristensen
|
d46148c045
|
add test case
|
2020-05-12 14:23:28 +02:00 |
|
Erik Krogh Kristensen
|
3ce60733cc
|
add test case
|
2020-05-11 13:11:24 +02:00 |
|
Erik Krogh Kristensen
|
945fe45b6f
|
all split()[0] are safe for url-redirect
|
2020-05-07 10:55:17 +02:00 |
|
Erik Krogh Kristensen
|
a3fb13882b
|
Merge branch 'master' into SplitFPs
|
2020-05-07 10:51:11 +02:00 |
|
Esben Sparre Andreasen
|
344f0c36b0
|
JS: update expected output
|
2020-05-06 11:18:14 +02:00 |
|
Erik Krogh Kristensen
|
bffb12725b
|
add test and change-note to prototype-polution
|
2020-05-05 13:49:11 +02:00 |
|
Erik Krogh Kristensen
|
38db731e0b
|
add change note and new test for js/incomplete-url-scheme-check
|
2020-05-05 13:38:27 +02:00 |
|
Erik Krogh Kristensen
|
8711a8744c
|
update expected output
|
2020-05-05 13:27:32 +02:00 |
|
Esben Sparre Andreasen
|
304b013f88
|
JS: query and tests for unsafe HTML expansion
|
2020-05-05 10:32:16 +02:00 |
|
Erik Krogh Kristensen
|
4b8b0cb379
|
update expected output
|
2020-05-05 09:13:21 +02:00 |
|
Erik Krogh Kristensen
|
7af19559d4
|
add test case for location.split("?")[0] for DomBasedXss
|
2020-05-05 09:13:21 +02:00 |
|
Erik Krogh Kristensen
|
4dcf944ccd
|
use StringSplitCall in TaintedPath
|
2020-05-05 09:13:21 +02:00 |
|
Erik Krogh Kristensen
|
eb7e0d6a62
|
still flag single-expression files that contain a function
|
2020-05-04 18:37:26 +02:00 |
|
Erik Krogh Kristensen
|
659d40e08d
|
add test to make sure sanitizer is not too broad
|
2020-05-04 09:49:14 +02:00 |
|
Erik Krogh Kristensen
|
291134be66
|
add failing test
|
2020-05-04 09:48:29 +02:00 |
|
semmle-qlci
|
2b055de4d6
|
Merge pull request #3154 from erik-krogh/ImplicitConv
Approved by asgerf
|
2020-04-29 16:05:19 +01:00 |
|
Esben Sparre Andreasen
|
04b5a794f1
|
Merge pull request #3313 from esbena/js/typical-bad-sanitizer
New query: Incomplete HTML attribute sanitization
|
2020-04-27 14:31:13 +02:00 |
|
Esben Sparre Andreasen
|
89613dbd23
|
JS: add query for incomplete HTML attribute sanitization
|
2020-04-24 09:17:46 +02:00 |
|
Erik Krogh Kristensen
|
ee43db1b58
|
slightly expand the $().each model
|
2020-04-23 16:49:47 +02:00 |
|
Erik Krogh Kristensen
|
448ed150df
|
allow the empty string to flow to a JQuery XSS sink
|
2020-04-23 16:45:37 +02:00 |
|
Erik Krogh Kristensen
|
ce106981b3
|
add tests
|
2020-04-23 14:24:33 +02:00 |
|
Erik Krogh Kristensen
|
d8c498bd15
|
add NOT OK comment
Co-Authored-By: Esben Sparre Andreasen <esbena@github.com>
|
2020-04-23 12:17:25 +02:00 |
|
Erik Krogh Kristensen
|
e1423b0fa5
|
add test for jGrowl
|
2020-04-23 11:58:06 +02:00 |
|
Erik Krogh Kristensen
|
ac26741816
|
reuse existing SanitizerGuard from UnsafeJQueryPlugin
|
2020-04-22 14:16:15 +02:00 |
|
Erik Krogh Kristensen
|
8811455d49
|
Merge remote-tracking branch 'upstream/master' into XssDom
|
2020-04-22 10:20:40 +02:00 |
|
Erik Krogh Kristensen
|
59b94b3d1b
|
revert back to having 2 separate cases in JQuery::MethodCall
|
2020-04-21 13:08:06 +02:00 |
|
Erik Krogh Kristensen
|
12f4ce8111
|
merge two cases of jQuery method calls
|
2020-04-20 13:28:55 +02:00 |
|
Erik Krogh Kristensen
|
2632699397
|
Merge branch 'master' of git.semmle.com:Semmle/ql into Mispelled
|
2020-04-18 17:58:57 +02:00 |
|
Erik Krogh Kristensen
|
427c32f211
|
report a local variable as the misspelling if there any many occourances of the global
|
2020-04-17 11:25:23 +02:00 |
|
Erik Krogh Kristensen
|
14b551f887
|
Xss through DOM
|
2020-04-17 10:54:14 +02:00 |
|
Erik Krogh Kristensen
|
eca98b42d2
|
basic support for util.promisify for NodeJSFileSystemAccess
|
2020-04-17 09:54:37 +02:00 |
|
Erik Krogh Kristensen
|
e8dc77d508
|
add support for util.promisify with child_process calls
|
2020-04-15 19:16:30 +02:00 |
|
Asger Feldthaus
|
2c6beadf68
|
JS: Recognize more forms of scheme checks
|
2020-04-06 12:30:03 +01:00 |
|