Anders Schack-Mulligen
|
f3f968ce6d
|
Dataflow: Rename predicates.
|
2020-11-13 15:09:27 +01:00 |
|
Anders Schack-Mulligen
|
aab5263c6a
|
Dataflow: Add modules.
|
2020-11-13 15:09:22 +01:00 |
|
Porcupiney Hairs
|
402a320a55
|
include suggestions from review.
|
2020-11-13 18:07:42 +05:30 |
|
Porcupiney Hairs
|
4b25532b9f
|
include suggestions from review.
|
2020-11-13 17:55:56 +05:30 |
|
Porcupiney Hairs
|
eb6d6113d9
|
minor nit.
|
2020-11-13 00:39:09 +05:30 |
|
Porcupiney Hairs
|
f8de94e906
|
refactor SpringWebClient
|
2020-11-13 00:32:27 +05:30 |
|
Porcupiney Hairs
|
2525cfd786
|
include suggestions from review.
|
2020-11-13 00:28:06 +05:30 |
|
james
|
9fc84f8061
|
Merge branch 'rc/1.26' into main-126-merge
|
2020-11-12 09:55:32 +00:00 |
|
luchua-bc
|
dcb7324643
|
Add the constraint that the caller method must throw an exception
|
2020-11-11 16:47:53 +00:00 |
|
Alvaro Muñoz
|
30d8dce389
|
check that either there are no custom message interpolator configured, or there is at least one that is insecure
|
2020-11-11 12:53:54 +01:00 |
|
Alvaro Muñoz
|
c3bc0d6c15
|
Apply formatting
|
2020-11-11 12:06:39 +01:00 |
|
Alvaro Muñoz
|
5b1858a514
|
Do not report the issue only if all message interpolators are secure
|
2020-11-11 11:50:15 +01:00 |
|
luchua-bc
|
018d5c46da
|
Simplify the query
|
2020-11-10 21:07:44 +00:00 |
|
Jonas Jensen
|
fc764db8e1
|
Merge pull request #4643 from nickrolfe/getFileBySourceArchiveName
Replace getEncodedFile with shared getFileBySourceArchiveName predicate
|
2020-11-10 17:36:29 +01:00 |
|
Nick Rolfe
|
ac4a1f1d9b
|
Update comment to be a QLDoc comment
|
2020-11-10 14:14:27 +00:00 |
|
Nick Rolfe
|
1e1eb7ee33
|
Replace getEncodedFile with shared getFileBySourceArchiveName predicate
While also making it work with paths for databases created on Windows.
|
2020-11-10 13:55:27 +00:00 |
|
Anders Schack-Mulligen
|
89ef6ea4eb
|
C++/C#/Java/JavaScript/Python: Autoformat set literals.
|
2020-11-10 13:32:27 +01:00 |
|
Alvaro Muñoz
|
02cf49a773
|
apply codeql formatting
|
2020-11-10 11:46:42 +01:00 |
|
Alvaro Muñoz
|
24a47fbb0f
|
additional qldoc commentes
|
2020-11-10 10:48:47 +01:00 |
|
Alvaro Muñoz
|
3545edb92c
|
address code review suggestions
|
2020-11-10 10:45:14 +01:00 |
|
Porcupiney Hairs
|
38de9b6433
|
add request forgery query
|
2020-11-10 01:19:35 +05:30 |
|
luchua-bc
|
bc899b6337
|
Move common code to a library and add more test cases
|
2020-11-09 14:14:54 +00:00 |
|
luchua-bc
|
b10552aa2e
|
Specify exported Android components for local Android DoS
|
2020-11-09 14:10:01 +00:00 |
|
luchua-bc
|
76a0db84ee
|
Query for detecting Local Android DoS caused by NFE
|
2020-11-09 14:10:00 +00:00 |
|
Anders Schack-Mulligen
|
31ec79819e
|
Merge pull request #4631 from luchua-bc/java-nfe-library
Java: Factor NumberFormatException out into a library file
|
2020-11-09 13:50:31 +01:00 |
|
luchua-bc
|
a83f9ced96
|
Change the query to only catch the common exception rethrown case
|
2020-11-09 12:07:43 +00:00 |
|
luchua-bc
|
d765c7bbb2
|
Update qldoc
|
2020-11-09 11:23:48 +00:00 |
|
luchua-bc
|
d568eb635f
|
Update qldoc
|
2020-11-06 15:33:26 +00:00 |
|
luchua-bc
|
450ff26694
|
Convert the query to a library
|
2020-11-06 13:25:00 +00:00 |
|
Alvaro Muñoz
|
9db340c9ca
|
add some improvements to the bean validation query
|
2020-11-06 13:08:45 +01:00 |
|
Anders Schack-Mulligen
|
cb77e460ae
|
Merge pull request #4600 from porcupineyhairs/urirefactor
Java : Refactor all instances of `java.net.URI` into TypeUri
|
2020-11-06 09:35:09 +01:00 |
|
Anders Schack-Mulligen
|
45d117b68e
|
Merge pull request #4603 from pwntester/new_deser_sink
New UnsafeDeserialization sink and improvements to SnakeYaml sink
|
2020-11-05 13:09:15 +01:00 |
|
Alvaro Muñoz
|
f103955f38
|
change qldoc formating according to LSP suggestion
|
2020-11-05 11:48:26 +01:00 |
|
Alvaro Muñoz
|
302062b670
|
Merge branch 'new_deser_sink' of https://github.com/pwntester/ql into new_deser_sink
|
2020-11-04 18:58:57 +01:00 |
|
Alvaro Muñoz
|
6fef63306e
|
add qldoc
|
2020-11-04 18:58:41 +01:00 |
|
Porcupiney Hairs
|
0a028dcb47
|
Java : Refactor all instances of java.net.URI into TypeUri
|
2020-11-04 18:23:26 +05:30 |
|
Alvaro Muñoz
|
aa7b87aa33
|
Update java/change-notes/2020-11-04-commonslang-unsafe-deserialization-sinks.md
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2020-11-04 10:58:27 +01:00 |
|
Alvaro Muñoz
|
b284141a16
|
Merge branch 'new_deser_sink' of https://github.com/pwntester/ql into new_deser_sink
|
2020-11-04 10:51:07 +01:00 |
|
Alvaro Muñoz
|
436563d914
|
ChangeNote for new unsafe deserialization sinks
|
2020-11-04 10:50:50 +01:00 |
|
Anders Schack-Mulligen
|
22b4df0f3c
|
Merge pull request #4512 from luchua-bc/sensitive-broadcast
Java: Sensitive broadcast
|
2020-11-04 10:47:48 +01:00 |
|
Alvaro Muñoz
|
6f78b725e6
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2020-11-04 10:43:37 +01:00 |
|
Anders Schack-Mulligen
|
14c4d8d565
|
Java: Add change note for #3812.
|
2020-11-04 10:15:08 +01:00 |
|
Anders Schack-Mulligen
|
26495225e0
|
Update java/ql/src/experimental/Security/CWE/CWE-927/SensitiveBroadcast.qhelp
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
|
2020-11-04 10:05:55 +01:00 |
|
luchua-bc
|
3f0cdb6a1a
|
Update qldoc and comments
|
2020-11-03 19:40:28 +00:00 |
|
luchua-bc
|
fa54c23a83
|
Handle the edge case that an exception is rethrown in a catch clause
|
2020-11-03 16:31:12 +00:00 |
|
Anders Schack-Mulligen
|
92494441a7
|
Merge pull request #4554 from aschackmull/dataflow/reverse-partial
Dataflow: Add support reverse partial flow exploration.
|
2020-11-03 15:34:30 +01:00 |
|
luchua-bc
|
f8fd2ea821
|
Add qldoc and autoformat query
|
2020-11-03 12:23:40 +00:00 |
|
Anders Schack-Mulligen
|
89361a3b75
|
Merge pull request #3812 from luchua-bc/java-android-remote-source
Java: Add remote source of Android intent extra
|
2020-11-03 09:35:40 +01:00 |
|
Anders Schack-Mulligen
|
2971784f9c
|
Dataflow: Add missing qldoc and sync.
|
2020-11-03 09:21:48 +01:00 |
|
Anders Schack-Mulligen
|
7eb64aa998
|
Dataflow: Code review fixes.
|
2020-11-03 09:16:20 +01:00 |
|