Owen Mansel-Chan
|
fdd1e3fefe
|
Use MaD models for unsafe deserialization sinks when possible
Many of the unsafe deserialization sinks have to stay defined in QL
because they have custom logic that cannot be expressed in MaD models.
|
2025-07-16 14:42:07 +01:00 |
|
Owen Mansel-Chan
|
8e4bd1a102
|
Add sink for ObjectInput.readObject to make test pass
|
2025-07-11 11:05:38 +01:00 |
|
Owen Mansel-Chan
|
34fae324a0
|
Add test for ObjectInput.readObject
|
2025-07-11 11:03:47 +01:00 |
|
Nora Dimitrijević
|
4412335223
|
Java: convert UnsafeDeserialization test to .qlref
|
2025-06-24 16:42:14 +02:00 |
|
Jeroen Ketema
|
89d20fd086
|
Java: Update expected test results
|
2024-12-03 19:18:59 +01:00 |
|
Jeroen Ketema
|
49993b023e
|
Java: Rewrite inline expectation tests to use parameterized module
|
2023-06-09 10:42:17 +02:00 |
|
Artem Smotrakov
|
3856527d14
|
Refactored tests for unsafe deserialization
|
2021-07-16 18:26:06 +02:00 |
|
Artem Smotrakov
|
c98f1a479e
|
Better taint propagation in UnsafeTypeConfig
|
2021-07-09 10:24:15 +02:00 |
|
Artem Smotrakov
|
aefd21075b
|
Added tests for UnsafeDeserialization.ql and Jackson
|
2021-07-09 10:24:10 +02:00 |
|
haby0
|
363ad5b470
|
Fix error
|
2021-06-17 17:36:35 +08:00 |
|
haby0
|
3dd851fffb
|
expected
|
2021-06-17 15:20:03 +08:00 |
|
haby0
|
c1ada6d85b
|
Merge branch 'main' into java/UnsafeDeserialization
|
2021-06-16 16:37:03 +08:00 |
|
haby0
|
60fc607449
|
Modify ql
|
2021-05-14 18:17:05 +08:00 |
|
haby0
|
12f47bcf24
|
Add UnsafeDeserialization
|
2021-05-12 12:37:16 +08:00 |
|
Anders Schack-Mulligen
|
175c71221a
|
Java: Adjust some test output with more edges/nodes.
|
2021-04-19 14:06:27 +02:00 |
|
Alvaro Muñoz
|
00a0b12dad
|
update expected results
|
2021-02-15 11:23:40 +01:00 |
|
Anders Schack-Mulligen
|
4be731d2ab
|
Java: Adjust reference to static method and add test.
|
2020-11-16 11:47:58 +01:00 |
|
Tom Hvitved
|
7f6e253425
|
Java: Update expected test output
|
2019-10-04 11:09:44 +02:00 |
|
Anders Schack-Mulligen
|
2d620698d8
|
Java: Adjust qltest expected output.
|
2019-09-12 11:00:49 +02:00 |
|
Anders Schack-Mulligen
|
deb61d6f29
|
Java: Update test output.
|
2018-11-16 13:48:50 +01:00 |
|
Pavel Avgustinov
|
846c9d5860
|
Migrate Java code to separate QL repo.
|
2018-08-30 10:48:05 +01:00 |
|