Marcono1234
f477e09190
Clarify Wildcard.hasUpperBound() doc
2020-08-06 23:15:16 +02:00
Remco Vermeulen
3ae3a879d2
Fix qldoc grammar and style mistakes
...
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com >
2020-08-06 23:00:03 +02:00
Arthur Baars
f16c263393
Java: remove security tag from java/integer-multiplication-cast-to-long
2020-08-06 17:42:01 +02:00
Remco Vermeulen
408db412dc
Add missing predicate qldoc
2020-08-06 13:29:02 +02:00
Remco Vermeulen
5a819422c1
Reuse Unit class from TaintTracking
2020-08-06 12:02:34 +02:00
Remco Vermeulen
7f7ad88dea
Limit LdapAdditionalTaintStep to Ldap configuration
2020-08-06 11:35:03 +02:00
Anders Schack-Mulligen
205dd1aead
Merge pull request #3881 from intrigus-lgtm/more-pathcreations
...
Java: Centralize and model additional path creations.
2020-08-06 11:21:39 +02:00
luchua-bc
b821f918e5
Address issues with matching empty host and host in a concatenated string
2020-08-06 01:53:29 +00:00
luchua-bc
9a8eed8440
Enhance address match
2020-08-05 19:57:31 +00:00
intrigus
1011325cf7
Accept test changes.
2020-08-05 21:45:41 +02:00
Remco Vermeulen
a1411407c1
Consolidate sanitizers into default sanitizer
2020-08-05 17:07:05 +02:00
Remco Vermeulen
0c09d66d43
Consolidate different sinks into a default sink.
2020-08-05 16:53:50 +02:00
Anders Schack-Mulligen
9e78341e43
Merge pull request #3928 from rvermeulen/java-importable-cwe-113
...
Java: Move `HeaderSplittingSink` and `WhitelistedSource` into importable library
2020-08-05 10:16:00 +02:00
Anders Schack-Mulligen
32d9d270fc
Merge pull request #3948 from aibaars/java-3941
...
Java: stack trace exposure: address false positives
2020-08-05 09:31:01 +02:00
Anders Schack-Mulligen
68441bdf99
Merge pull request #3987 from Marcono1234/patch-1
...
[Java] Improve InsecureJavaMail.qhelp references
2020-08-04 12:12:38 +02:00
Luke Cartey
5a96ee1a7b
Remove parameter names from signatures
...
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com >
2020-08-04 09:41:40 +01:00
Luke Cartey
368572f1f0
Update java/ql/src/Security/CWE/CWE-020/UntrustedDataToExternalAPI.qhelp
...
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com >
2020-08-04 09:40:59 +01:00
Luke Cartey
7928a02424
Add missing full stop.
...
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com >
2020-08-04 09:40:51 +01:00
Luke Cartey
e0c081a2af
Add missing </p> tag
...
Co-authored-by: Felicity Chapman <felicitymay@github.com >
2020-08-04 09:40:28 +01:00
Anders Schack-Mulligen
cdea0f05b0
Merge pull request #3946 from aibaars/util-collections-2
...
Java: Clean up ContainerFlow: address outstanding comments
2020-08-04 10:27:22 +02:00
luchua-bc
ff0dacf1d7
Optimize the TaintTracking
2020-08-03 00:52:47 +00:00
luchua-bc
b65a033302
Shorten the regex private domain match
2020-08-01 03:42:13 +00:00
luchua-bc
ff58abb7d3
Revamp the sink code
2020-08-01 03:25:02 +00:00
luchua-bc
81de1b14d9
Revamp the source of path query
2020-07-30 19:16:48 +00:00
Arthur Baars
7e72ef350e
Merge pull request #3975 from aibaars/lgtm-suites
...
CodeQL: complete LGTM suites
2020-07-30 18:39:01 +02:00
Arthur Baars
5bad003c0c
Add qlpack.yml files for example queries
2020-07-29 16:57:04 +02:00
Marcono1234
5942bc6a43
Improve InsecureJavaMail.qhelp references
2020-07-29 01:45:27 +02:00
Arthur Baars
c4041e55ba
CodeQL: complete LGTM suites
2020-07-28 20:40:44 +02:00
luchua-bc
5520504658
Update expected results
2020-07-28 15:41:23 +00:00
luchua-bc
a91cc9b7ec
Convert the query to path-problem
2020-07-28 15:36:12 +00:00
luchua-bc
7f911f00ee
Rename to insecure basic auth
2020-07-28 11:40:21 +00:00
luchua-bc
248628b11e
Enhance basic auth string search with a recursive method
2020-07-27 20:31:07 +00:00
luchua-bc
3a23451395
Enhance the query
2020-07-27 18:50:47 +00:00
luchua-bc
01fb51829c
Unsecure basic authentication
2020-07-24 20:35:09 +00:00
Remco Vermeulen
3320061178
Add and adjust QL docs for classes and predicates
2020-07-22 16:04:55 +02:00
Remco Vermeulen
2c42d3cca5
Extract additional taint steps
...
This is done for logical cohesion. We already have the capability of
extending additional taint steps by extending
`TaintTracking::AdditionalTaintStep`.
2020-07-22 16:04:55 +02:00
Remco Vermeulen
57e7411c0a
Extract Ldap injection sanitizers to importable lib
...
This includes a new abstract class that represents all the Ldap injection
santizers and can be used to add additional santizers through
extension.
2020-07-22 16:04:55 +02:00
Remco Vermeulen
0d5f9113a3
Extract ldap injection sink into importable library
2020-07-22 16:04:55 +02:00
Remco Vermeulen
c2733ad22e
Apply grammar suggestions
...
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com >
2020-07-20 14:55:00 +02:00
intrigus
f94055fa2c
Move tainted path ad-hoc guard back.
2020-07-19 00:19:29 +02:00
intrigus
33526f61a8
Make path creation subclasses private.
2020-07-19 00:11:04 +02:00
intrigus
b705f7f3e9
Improve "PathCreation" Test.
2020-07-19 00:10:39 +02:00
intrigus
4570444c7e
Rename to getAnInput and clarify doc.
2020-07-19 00:10:13 +02:00
Arthur Baars
67b6018079
Merge pull request #3729 from luchua-bc/java-hardcoded-aws-credentials
...
Java: Hardcoded AWS credentials
2020-07-13 18:04:42 +02:00
Arthur Baars
c585b2e483
Java: stack trace exposure: address false positives
2020-07-13 15:26:55 +02:00
luchua-bc
12803f1f53
Merge Hardcoded AWS Credentials check into the mail source folder
2020-07-13 12:22:34 +00:00
Arthur Baars
b1e604b490
Java: treat Stack.push as data flow instead of taint flow
2020-07-13 11:36:34 +02:00
Arthur Baars
a484aff76d
Java: improve comments
2020-07-13 11:09:05 +02:00
Jonathan Leitschuh
1f6615b3b8
Merge branch 'master' into feat/JLL/jOOQ_SQL_injection
...
* master: (485 commits)
C++: Remove @stmt_while from the TConditionalStmt union type.
C++: Remove abstract classes from Stmt.qll
Drop Map.merge as taint step
Add the printAst.ql contextual query for C++
Fix modelling of Stack.push
C#: Sync identical files
C++: Replace getResultType() with getResultIRType() in IR dataflow
C++: Replace getResultType() with getResultIRType() in IR range analysis
C++: Introduce isSigned() and isUnsigned() predicates on IRIntegerType to mirror IntegralType
Add missing java import
Add missing java import
Mark ServletUrlRedirectSink private
Java: model Object.clone
Add file-level qldoc
Optimize imports
Join ServletUrlRedirectSink with UrlRedirectSink
Extend UrlRedirectSink from DataFlow::Node
Remove superfluous imports
Java: ContainerFlow add comments
Generalize QueryInjectionSink
...
2020-07-10 14:37:41 -04:00
Anders Schack-Mulligen
a1d272e870
Merge pull request #3918 from aibaars/organise-container-flow
...
Java: Clean up ContainerFlow, consider more methods
2020-07-10 14:19:44 +02:00