Jonathan Leitschuh
|
ba4a562c9a
|
Update PrintAst.actual with new test output
|
2021-01-04 23:37:58 -05:00 |
|
luchua-bc
|
195755d687
|
Revamp the query to be more selective
|
2021-01-05 00:04:08 +00:00 |
|
luchua-bc
|
496db4b42f
|
Factor isGetServletMethod into the servlet library
|
2021-01-04 16:14:13 +00:00 |
|
Jonathan Leitschuh
|
028e4756bb
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-01-04 10:13:52 -05:00 |
|
luchua-bc
|
c069a5b4c6
|
Factor private host regex into the networking library and enhance the query
|
2021-01-04 14:51:32 +00:00 |
|
Jonathan Leitschuh
|
54950c2f42
|
Add MethodAccessSystemGetProperty predicate
|
2021-01-01 20:07:45 -05:00 |
|
luchua-bc
|
ffe9d4a310
|
Sensitive GET Query
|
2020-12-26 16:51:30 +00:00 |
|
Rasmus Wriedt Larsen
|
874af7637f
|
Java: Fix taint-step handling for untrusted-data-external-api
The previous implementation would not handle any `AdditionalTaintStep`
subclasses.
|
2020-12-22 11:02:50 +01:00 |
|
luchua-bc
|
4ec78d04f8
|
Insecure LDAP authentication
|
2020-12-21 00:15:15 +00:00 |
|
luchua-bc
|
bfb138d415
|
Update qldoc
|
2020-12-17 14:42:14 +00:00 |
|
luchua-bc
|
7b44ee50ea
|
Revamp the functions to have a string parameter
|
2020-12-17 14:26:13 +00:00 |
|
luchua-bc
|
b44f01a87b
|
Enhance the check for embedded passwords
|
2020-12-17 03:47:38 +00:00 |
|
luchua-bc
|
bed8a68d28
|
Exclude broken algorithms from the list of secure algorithms
|
2020-12-17 00:41:23 +00:00 |
|
luchua-bc
|
6b77922a25
|
Fix typo and update qldoc
|
2020-12-16 14:04:45 +00:00 |
|
luchua-bc
|
d7facb42d6
|
Add missing broken crypto algorithms
|
2020-12-16 04:32:11 +00:00 |
|
luchua-bc
|
523f0fb247
|
Enhance the query and update qldoc
|
2020-12-14 17:01:30 +00:00 |
|
luchua-bc
|
d469e9b24e
|
Format the code and minor text change
|
2020-12-13 21:15:18 +00:00 |
|
luchua-bc
|
e27ccd0a81
|
Format the code and update qldoc
|
2020-12-13 02:33:03 +00:00 |
|
luchua-bc
|
7ba237120b
|
Password in Java EE configuration files
|
2020-12-12 05:15:04 +00:00 |
|
Joe Farebrother
|
732542adcb
|
Add change note
|
2020-12-09 16:41:31 +00:00 |
|
Joe Farebrother
|
24dc631a8f
|
Java: Fix false positive in XXE query
|
2020-12-08 16:38:42 +00:00 |
|
Joe Farebrother
|
2fd5d26b1b
|
Add FP as a test case
|
2020-12-08 16:37:53 +00:00 |
|
yo-h
|
54d7cac46d
|
Merge pull request #4718 from aschackmull/java/cleanup-deprecated
Java: Remove some deprecated classes.
|
2020-12-04 11:17:14 -05:00 |
|
yo-h
|
a5393b4661
|
Merge pull request #4746 from aschackmull/java/ssa-perf
Java: Improve performance of SSA.
|
2020-12-04 11:16:39 -05:00 |
|
Anders Schack-Mulligen
|
0cc324b715
|
Merge pull request #3839 from luchua-bc/uncaught-servlet-exception
Java: Uncaught servlet exception
|
2020-12-02 15:12:59 +01:00 |
|
Anders Schack-Mulligen
|
0175a596ef
|
Update java/ql/src/experimental/Security/CWE/CWE-600/UncaughtServletException.ql
|
2020-12-02 13:33:59 +01:00 |
|
yo-h
|
cdeeefc235
|
Merge commit '8f2094f' into yo-h/java15-merge
|
2020-12-01 17:47:58 -05:00 |
|
Anders Schack-Mulligen
|
8f2094f0bf
|
Autoformat.
|
2020-11-30 14:42:38 +01:00 |
|
Anders Schack-Mulligen
|
88e0759365
|
Java: Change RemoteUserInput to private instead of removing.
|
2020-11-30 13:40:53 +01:00 |
|
Anders Schack-Mulligen
|
5a66d6ab93
|
Java: Improve performance of SSA.
|
2020-11-30 11:26:03 +01:00 |
|
Anders Schack-Mulligen
|
931322e4c5
|
Merge pull request #4668 from aschackmull/dataflow/refactor-pruning
Dataflow: Refactor pruning stages.
|
2020-11-30 09:37:04 +01:00 |
|
yo-h
|
7e8bc4a61b
|
Merge commit '2fa9037' into yo-h/java15-merge
|
2020-11-29 18:42:20 -05:00 |
|
luchua-bc
|
ad0ac5b874
|
Change kind to problem
|
2020-11-27 16:43:57 +00:00 |
|
Anders Schack-Mulligen
|
028a72bcdd
|
Merge pull request #4610 from luchua-bc/java-nfe-local-android-dos
Java: Query to detect Local Android DoS caused by NFE
|
2020-11-27 14:20:23 +01:00 |
|
Anders Schack-Mulligen
|
fec9758252
|
Dataflow: Sync.
|
2020-11-27 12:16:43 +01:00 |
|
Anders Schack-Mulligen
|
8f4fce185b
|
Dataflow: Review fixes.
|
2020-11-27 12:16:28 +01:00 |
|
Jonas Jensen
|
ad4b2beafa
|
Merge pull request #4727 from criemen/remove-abstract-classes
C++/C#/JS/Python/Java XML.qll: Remove abstract from class hierarchy.
|
2020-11-27 08:17:21 +01:00 |
|
Anders Schack-Mulligen
|
2234d665ce
|
Add manual magic
|
2020-11-26 13:55:20 -05:00 |
|
yo-h
|
9bb949a8b1
|
Java: make some SMAP predicates private and add QLDoc
|
2020-11-26 13:55:19 -05:00 |
|
yo-h
|
c077ca3fc9
|
Java: add dbscheme upgrade script for SMAP relations
|
2020-11-26 13:55:19 -05:00 |
|
yo-h
|
f9e78085ac
|
Java: add dbscheme stats for SMAP relations
|
2020-11-26 13:55:18 -05:00 |
|
yo-h
|
edb41655b4
|
Java: incorporate SMAP locations into Top.hasLocationInfo
|
2020-11-26 13:55:17 -05:00 |
|
yo-h
|
e2419e8fed
|
Java: add SMAP relations to dbscheme
|
2020-11-26 13:55:17 -05:00 |
|
luchua-bc
|
a83ddd66eb
|
Add comments about how the future promotion should go
|
2020-11-26 17:41:46 +00:00 |
|
luchua-bc
|
7ad031ca70
|
Move to experimental and update qldoc
|
2020-11-26 17:09:53 +00:00 |
|
Anders Schack-Mulligen
|
f70072a2db
|
Merge pull request #3454 from porcupineyhairs/javaSSRf
Java : add request forgery query
|
2020-11-26 08:52:15 +01:00 |
|
yo-h
|
eedc385b37
|
Java 15: adjust test options
|
2020-11-26 00:14:24 -05:00 |
|
Cornelius Riemenschneider
|
3bfb398516
|
Autoformat XML.qll.
|
2020-11-25 18:20:50 +01:00 |
|
Cornelius Riemenschneider
|
7eec988fb5
|
XML.qll: Remove abstract from class hierarchy.
|
2020-11-25 17:22:03 +01:00 |
|
luchua-bc
|
a49160423b
|
Enhance the query and add more test cases
|
2020-11-25 04:33:26 +00:00 |
|