Erik Krogh Kristensen
|
8d556ed1e1
|
Update python/ql/lib/semmle/python/security/BadTagFilterQuery.qll
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2021-09-28 23:04:28 +02:00 |
|
luciaromeroML
|
1fc58e51a3
|
adding suggestion that removes sanitizer for unknown base urls
|
2021-09-27 17:37:36 -03:00 |
|
luciaromeroML
|
1f2618b893
|
new test case for unknown base url
|
2021-09-27 17:37:11 -03:00 |
|
Rasmus Wriedt Larsen
|
ded3088529
|
Python/JS: Recognize SHA-3 hash functions
Official names are SHA3-224, SHA3-256, SHA3-384, SHA3-512 as per
https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
|
2021-09-27 12:08:40 +02:00 |
|
Erik Krogh Kristensen
|
805d1d170c
|
do not filter away regular expressions with lookbehinds
|
2021-09-22 17:14:29 +02:00 |
|
Erik Krogh Kristensen
|
99ed4a1a89
|
add a bad-tag-filter query for Python and JavaScript
|
2021-09-21 15:04:03 +02:00 |
|
Erik Krogh Kristensen
|
c40ffab093
|
make isStartState public in ReDoSUtil
|
2021-09-21 12:14:21 +02:00 |
|
Erik Krogh Kristensen
|
672e4a3d72
|
cache TopLevel::isMinified
|
2021-09-21 12:13:37 +02:00 |
|
Erik Krogh Kristensen
|
60993214d5
|
cache isInterpretedAsRegExp
|
2021-09-21 12:13:37 +02:00 |
|
luciaromeroML
|
f348a5ce47
|
adding comments to some functions
|
2021-09-17 18:25:14 -03:00 |
|
luciaromeroML
|
25065bc986
|
simplifying sentence
|
2021-09-17 18:07:04 -03:00 |
|
luciaromeroML
|
0b0ac8317c
|
format ql code
|
2021-09-17 18:05:52 -03:00 |
|
valeria-meli
|
054218a381
|
Merge branch 'main' into javascript/ssrf
|
2021-09-17 17:08:52 -03:00 |
|
Erik Krogh Kristensen
|
5c73fed83a
|
fix dbsheme upgrade from TypeScript 4.4 PR
|
2021-09-15 22:38:27 +02:00 |
|
Erik Krogh Kristensen
|
3f736d3eb8
|
Merge pull request #6694 from erik-krogh/owasp-fixes
JS/Java: use the correct cwe tags
|
2021-09-15 13:46:35 +02:00 |
|
CodeQL CI
|
b228398b87
|
Merge pull request #6587 from erik-krogh/ts44
Approved by asgerf
|
2021-09-15 04:00:13 -07:00 |
|
Erik Krogh Kristensen
|
cf149bd8c8
|
add static_initializer as a stmt_parent
|
2021-09-15 11:54:30 +02:00 |
|
Erik Krogh Kristensen
|
0b83d033d7
|
add @static_initializer in the stats file
|
2021-09-15 11:33:05 +02:00 |
|
CodeQL CI
|
220f2ded85
|
Merge pull request #6698 from asgerf/js/template-self-assignment
Approved by esbena
|
2021-09-15 01:08:39 -07:00 |
|
Asger Feldthaus
|
b5db4047a0
|
JS: Exclude template files in SelfAssignment
|
2021-09-15 08:59:47 +02:00 |
|
Erik Krogh Kristensen
|
5a7785776c
|
add upgrade script
|
2021-09-14 20:43:07 +02:00 |
|
Erik Krogh Kristensen
|
fdbf5f73b1
|
add JS support for static initializers
|
2021-09-14 20:40:46 +02:00 |
|
Erik Krogh Kristensen
|
48b763c7e9
|
add qldoc to StaticInitializer::getBody
|
2021-09-14 20:40:46 +02:00 |
|
Erik Krogh Kristensen
|
e3ed6c2523
|
refactor StaticInitializer into it's own class
|
2021-09-14 20:40:45 +02:00 |
|
Erik Krogh Kristensen
|
ffd51e725f
|
add getter for static initializer blocks
|
2021-09-14 20:40:45 +02:00 |
|
Erik Krogh Kristensen
|
9585481d0b
|
add support for static initializer blocks in TypeScript
|
2021-09-14 20:40:45 +02:00 |
|
Erik Krogh Kristensen
|
59f15eb4eb
|
add tests for TypeScript 4.4 types
|
2021-09-14 20:40:45 +02:00 |
|
Erik Krogh Kristensen
|
3b6c8c5191
|
Merge branch 'main' into clipBoard
|
2021-09-14 20:21:37 +02:00 |
|
CodeQL CI
|
136d04390d
|
Merge pull request #6695 from erik-krogh/js-add-cwes
Approved by esbena
|
2021-09-14 11:19:35 -07:00 |
|
Erik Krogh Kristensen
|
b936a04826
|
add some fitting CWEs to existing queries
|
2021-09-14 14:59:24 +02:00 |
|
Erik Krogh Kristensen
|
6d12c4aab1
|
use the correct cwe tags
|
2021-09-14 14:42:23 +02:00 |
|
Tom Hvitved
|
63e28c57cd
|
JavaScript: Drop redundant columns from files and folders relations
|
2021-09-14 10:25:37 +02:00 |
|
Erik Krogh Kristensen
|
8569d261f7
|
add test
|
2021-09-13 20:43:31 +02:00 |
|
Erik Krogh Kristensen
|
8e98dcefb1
|
add clipboard data as a RemoteFlowSource
|
2021-09-13 20:43:31 +02:00 |
|
Erik Krogh Kristensen
|
3983aceb48
|
recognize types of the form "HTML%Element" as dom values
|
2021-09-13 20:43:31 +02:00 |
|
Erik Krogh Kristensen
|
bac80bf686
|
delete ClipboardXss.ql experimental query
|
2021-09-13 20:43:31 +02:00 |
|
Erik Krogh Kristensen
|
05cc6bcf8a
|
adjust regexp libraries to how unpaired surrogate are parsed now
|
2021-09-13 14:02:05 +01:00 |
|
Chris Smowton
|
f24d7c4212
|
Acknowledge new FPs due to the extractor using U+FFFD for unpaired surrogates
These were already misinterpreted, but the ReDoS code ignored them as they previously appeared to be `?` characters.
|
2021-09-13 14:02:05 +01:00 |
|
Chris Smowton
|
487ebdf173
|
Add test for Javascript literal with an unpaired surrogate character
|
2021-09-13 14:02:05 +01:00 |
|
CodeQL CI
|
e8fc3c8ead
|
Merge pull request #5888 from erik-krogh/casting
Approved by asgerf
|
2021-09-10 09:11:39 -07:00 |
|
CodeQL CI
|
27f2d417c1
|
Merge pull request #6652 from asgerf/js/type-tracking-through-callback
Approved by erik-krogh
|
2021-09-10 04:11:14 -07:00 |
|
Erik Krogh Kristensen
|
a756ffa3a6
|
use the new instanceof syntax for NodeJSClientRequest
|
2021-09-10 09:30:37 +02:00 |
|
rhysd
|
97ed9edd32
|
JS: Detect untrusted inputs in 'discussion' and 'discussion_comment' payloads
|
2021-09-10 10:42:58 +09:00 |
|
CodeQL CI
|
cd26d97dd7
|
Merge pull request #6549 from erik-krogh/moreDom
Approved by asgerf
|
2021-09-08 05:10:47 -07:00 |
|
Asger Feldthaus
|
db1de18cc2
|
JS: Support transitive callback-passing
|
2021-09-08 13:08:16 +02:00 |
|
Asger Feldthaus
|
ceaf2b3727
|
JS: Rename FlowSteps::callback -> exploratoryCallbackStep
|
2021-09-08 13:08:12 +02:00 |
|
Asger Feldthaus
|
7c94dd94e9
|
JS: Add type-tracking steps through callback args
|
2021-09-08 13:08:05 +02:00 |
|
Asger Feldthaus
|
1f6df4e70d
|
JS: Add callback type tracking test
|
2021-09-08 13:08:04 +02:00 |
|
CodeQL CI
|
5b229e9392
|
Merge pull request #6574 from asgerf/js/vue-api-graphs
Approved by erik-krogh
|
2021-09-07 05:53:30 -07:00 |
|
Erik Krogh Kristensen
|
85e1c87d14
|
use the new non-extending-subtypes syntax
|
2021-09-06 11:19:50 +02:00 |
|