Owen Mansel-Chan
|
5e89fce734
|
Avoid strange bug by commenting out two tests
|
2021-06-14 10:57:28 +01:00 |
|
Owen Mansel-Chan
|
8cf47f12b4
|
Model constructors of classes implementing MultivaluedMap
|
2021-06-14 10:56:35 +01:00 |
|
Joe Farebrother
|
678597f3f9
|
Update CSV rows for collection flow
|
2021-06-11 15:08:27 +01:00 |
|
Chris Smowton
|
76838809bb
|
Merge pull request #5818 from artem-smotrakov/rmi-deserialization
Java: Unsafe RMI deserialization
|
2021-06-11 13:43:07 +01:00 |
|
Joe Farebrother
|
04ffe80366
|
Add unit tests
|
2021-06-11 11:41:27 +01:00 |
|
Owen Mansel-Chan
|
e0130a932e
|
Update experimental query using NewCookie
|
2021-06-10 13:33:20 +01:00 |
|
Owen Mansel-Chan
|
c173b89529
|
Model NewCookie
|
2021-06-10 13:32:39 +01:00 |
|
Owen Mansel-Chan
|
ee6019a2d8
|
Fix tests for experimental httponly query
|
2021-06-10 13:31:28 +01:00 |
|
Owen Mansel-Chan
|
d5d27d5ccf
|
Duplicate tests for Jakarta
|
2021-06-10 10:43:40 +01:00 |
|
Owen Mansel-Chan
|
0ad35421f2
|
Comment out stubs (Jakarta)
|
2021-06-10 10:43:40 +01:00 |
|
Owen Mansel-Chan
|
318d1ea484
|
Stubs in javax-ws-rs-api-3.0.0
Generated using java-autostub
|
2021-06-10 10:43:39 +01:00 |
|
Owen Mansel-Chan
|
e6a6a8898b
|
Move Jax XSS sinks to JaxWS.qll and add tests
|
2021-06-10 10:43:39 +01:00 |
|
Owen Mansel-Chan
|
d1fe62d4d5
|
(Minor) Update comments to match ExternalFlow docs
|
2021-06-10 10:43:38 +01:00 |
|
Owen Mansel-Chan
|
1ae9d68409
|
Move and convert URL redirect sinks
Adds for them as well
|
2021-06-10 10:43:37 +01:00 |
|
Owen Mansel-Chan
|
f2ff2aa3e1
|
Add flow tests for JAX-RS
|
2021-06-10 10:43:37 +01:00 |
|
Owen Mansel-Chan
|
155d63d5f7
|
Add tests for JAX-RS
|
2021-06-10 10:43:36 +01:00 |
|
Owen Mansel-Chan
|
baa21c5bcf
|
Manually comment out parts of stubs
This is to avoid having to make more stubs, which we don't really need
|
2021-06-10 10:43:34 +01:00 |
|
Owen Mansel-Chan
|
caf96b01e1
|
Stubs in javax-ws-rs-api-2.1.1
Generated using java-autostub
|
2021-06-10 10:43:34 +01:00 |
|
Owen Mansel-Chan
|
2cb76fe407
|
Test JAX-WS endpoints
|
2021-06-08 15:12:04 +01:00 |
|
Owen Mansel-Chan
|
d9cf1aaf39
|
Add stubs for JAX-WS
|
2021-06-08 15:12:04 +01:00 |
|
Tony Torralba
|
48b0df4a3e
|
Add tests, minor bugfixes
|
2021-06-08 10:35:18 +02:00 |
|
Tony Torralba
|
d77d0c9e10
|
Added summaries for Spring PropertyValues
|
2021-06-07 17:35:03 +02:00 |
|
Anders Schack-Mulligen
|
96da85449d
|
Merge pull request #5823 from atorralba/promote-jexl-injection
Java: Promote JEXL Injection query from experimental
|
2021-06-07 10:03:12 +02:00 |
|
Chris Smowton
|
4ddf4558a7
|
Merged simplified query
|
2021-06-04 16:07:15 +02:00 |
|
Anders Schack-Mulligen
|
f73960da8f
|
Merge pull request #5788 from Marcono1234/marcono1234/stmt-toString
Java: Override toString() for statements
|
2021-06-04 12:41:03 +02:00 |
|
Anders Schack-Mulligen
|
60377a8f86
|
Merge pull request #5383 from smowton/smowton/feature/strbuilder-fluent-methods
Java: Add models for StrBuilder's fluent methods
|
2021-06-04 12:33:24 +02:00 |
|
Anders Schack-Mulligen
|
30cb80b341
|
Merge pull request #5181 from smowton/smowton/feature/commons-tostringbuilder
Java: Add models for Commons ToStringBuilder
|
2021-06-04 12:30:36 +02:00 |
|
Marcono1234
|
485b0be805
|
Java: Fix expected test output
|
2021-06-03 17:15:00 +02:00 |
|
Marcono1234
|
e0a45507f8
|
Java: Adjust toString() for statements
|
2021-06-03 16:27:36 +02:00 |
|
Marcono1234
|
7e778bc008
|
Java: Override toString() for statements
Additionally remove redundant QLDoc which is inherited anyways.
|
2021-06-03 16:27:35 +02:00 |
|
Anders Schack-Mulligen
|
bd9e3d0fa9
|
Merge pull request #5751 from aschackmull/java/collection-flow
Java: Convert all collection and array steps from taint flow to value flow.
|
2021-06-03 15:29:14 +02:00 |
|
Tony Torralba
|
56a429a5f9
|
Merge branch 'main' into promote-jexl-injection
|
2021-06-03 11:10:56 +02:00 |
|
Tony Torralba
|
34a8383c1a
|
Unused import
|
2021-06-03 10:22:53 +02:00 |
|
Anders Schack-Mulligen
|
8e6dd51f50
|
Merge pull request #5868 from Marcono1234/marcono1234/ignore-not-closing-char-array-closeable
Java: Ignore char array based closeables for CloseReader.ql and CloseWriter.ql
|
2021-06-02 15:00:59 +02:00 |
|
Anders Schack-Mulligen
|
8a20395857
|
Merge pull request #5940 from pwntester/main
Remove XSS sink for Java
|
2021-06-02 12:30:20 +02:00 |
|
Tony Torralba
|
d476459727
|
Use InlineExpectationsTest
|
2021-06-02 12:15:26 +02:00 |
|
Tony Torralba
|
59e6e1ffac
|
Moved from experimental
|
2021-06-02 09:58:30 +02:00 |
|
Anders Schack-Mulligen
|
dbe352f3ff
|
Java: Remove deprecated tests.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
901996f9fd
|
Java: Add collection flow test.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
43d1b0ab27
|
Java: Update qltests.
|
2021-06-01 11:47:52 +02:00 |
|
Anders Schack-Mulligen
|
a4661e1aca
|
Merge pull request #5704 from edvraa/regexj
Java: Regex injection
|
2021-06-01 11:45:59 +02:00 |
|
Alvaro Muñoz
|
735e4e4b7b
|
update failing tests
|
2021-05-28 15:13:18 +02:00 |
|
Timo Mueller
|
75f6ec1f0d
|
Updated test cases to include test for java10+ CREDENTIALS_FILTER_PATTERN constant
|
2021-05-25 17:08:58 +02:00 |
|
Timo Mueller
|
59ebe08c78
|
Added stup for RMIConnectorServer for valid test case
|
2021-05-25 16:40:41 +02:00 |
|
Artem Smotrakov
|
c837605c85
|
Added test cases with sanitizers for UnsafeDeserializationRmi.ql
|
2021-05-23 13:01:22 +02:00 |
|
Artem Smotrakov
|
d2e29fc72c
|
Renamed RmiUnsafeDeserialization.ql -> UnsafeDeserializationRmi.ql
|
2021-05-23 10:21:05 +02:00 |
|
Artem Smotrakov
|
e28f919f3d
|
Look for remote callable method only in RmiUnsafeDeserialization.ql
|
2021-05-23 10:21:05 +02:00 |
|
Artem Smotrakov
|
5ffe04d6a5
|
Updated expected output for RmiUnsafeDeserialization.java test
|
2021-05-23 10:21:04 +02:00 |
|
Artem Smotrakov
|
3d20330a92
|
More tests for RmiUnsafeDeserialization
|
2021-05-23 10:21:04 +02:00 |
|
Artem Smotrakov
|
ec6186a1c5
|
Draft of tests for RmiUnsafeDeserialization.ql
|
2021-05-23 10:21:04 +02:00 |
|