masterofnow
|
0fd09759df
|
Added sample java file for qhelp to render correctly.
|
2023-12-22 08:31:23 +08:00 |
|
masterofnow
|
cb5733d647
|
Apply suggestions from code review
Update to documentation.
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-22 08:25:05 +08:00 |
|
masterofnow
|
7162540faf
|
Added options, .qhelp and .expected file for unit test.
|
2023-12-21 19:57:37 +08:00 |
|
masterofnow
|
8dc522fb5f
|
Merge remote-tracking branch 'origin/LoadClassNoSignatureCheck' into LoadClassNoSignatureCheck
|
2023-12-21 12:15:06 +08:00 |
|
masterofnow
|
25c818f425
|
Added unit test files.
|
2023-12-21 12:13:00 +08:00 |
|
Tony Torralba
|
39708524e7
|
Minor fixes
- Query ID
- MethodAccess -> MethodCall
- Redundant import
- Formatting
|
2023-12-20 15:31:09 +01:00 |
|
masterofnow
|
e85c4b5bf6
|
Update query from code review feedback to express it as a dataflow problem.
|
2023-12-20 18:28:16 +08:00 |
|
masterofnow
|
4a77f45aa6
|
Minor adjustment to resolve error for codeql version 2.15.4
|
2023-12-16 12:41:39 +08:00 |
|
masterofnow
|
99b273d308
|
Apply suggestions from code review
Added suggestion from atorralba.
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-16 12:00:45 +08:00 |
|
masterofnow
|
e1b8fabf7f
|
Use global instead of local taint tracking.
|
2023-12-13 13:50:34 +08:00 |
|
masterofnow
|
8538c12267
|
Merge branch 'github:main' into LoadClassNoSignatureCheck
|
2023-12-13 13:47:40 +08:00 |
|
Tony Torralba
|
27be5ba14b
|
Merge pull request #15073 from atorralba/atorralba/java/remove-invalid-ognl-sinks
Java: Remove invalid OGNL sinks
|
2023-12-12 16:52:31 +01:00 |
|
Tony Torralba
|
fad53a25c0
|
Update java/ql/lib/ext/struts2.model.yml
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2023-12-12 14:58:47 +01:00 |
|
Tony Torralba
|
103110f9c2
|
Java: Remove invalid OGNL sinks
Fixes #15053
|
2023-12-12 13:39:51 +01:00 |
|
Edward Minnix III
|
06eef93f89
|
Docs review suggestions
|
2023-12-11 11:18:40 -05:00 |
|
Edward Minnix III
|
ce20c4ae03
|
Docs review suggestions
Co-authored-by: Ben Ahmady <32935794+subatoi@users.noreply.github.com>
|
2023-12-11 11:18:40 -05:00 |
|
Ed Minnix
|
7362158229
|
Fix test case
|
2023-12-11 11:18:40 -05:00 |
|
Ed Minnix
|
1271cd3348
|
Remove unnecessary crypto sinks
|
2023-12-11 11:18:40 -05:00 |
|
Ed Minnix
|
3ca039bc8f
|
Rename to InsecureRandomness
|
2023-12-11 11:18:40 -05:00 |
|
Ed Minnix
|
6e70e6c85a
|
Use pre-exisiting type for SecureRandom
|
2023-12-11 11:18:39 -05:00 |
|
Edward Minnix III
|
4678302edb
|
Update query metadata
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
bbf99375c7
|
Alter cookie sinks to instead focus on creation of a cookie
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
4bdf2b5e18
|
Bump change note date
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
b9d2a26e6e
|
Move ESAPI models into the Weak Randomness query
These models don't need to apply to all queries. So instead they are
better suited to be within the weak randomness query itself.
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
7f3995f524
|
Remove extra encryption-iv models
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
7241e0920c
|
Replace convertBytesToString with models
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
e9ca4a25d4
|
Update to new MethodCall name
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
a1e9564cc5
|
Add more sources
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
b8b2de2f3c
|
Remove use of crypto-parameter sink kind
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
646254c9b2
|
Add credentials sinks from SensitiveApi
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
057a74d914
|
Remove unnused class
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
fb875f5095
|
More variety of test cases
|
2023-12-11 11:18:39 -05:00 |
|
Ed Minnix
|
ba3c38c226
|
Restrict addCookie to specific interface
|
2023-12-11 11:18:38 -05:00 |
|
Ed Minnix
|
dc3e4cd928
|
Refactored method accesses to the RandomDataSource library
|
2023-12-11 11:18:38 -05:00 |
|
Ed Minnix
|
ce7690b53f
|
Make imports private
|
2023-12-11 11:18:38 -05:00 |
|
Edward Minnix III
|
bc0655573f
|
Simplifications
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2023-12-11 11:18:38 -05:00 |
|
Ed Minnix
|
14fdfa4428
|
Add new sink kind and change note
|
2023-12-11 11:18:38 -05:00 |
|
Ed Minnix
|
0313f39229
|
Cryptographic sinks
|
2023-12-11 11:18:38 -05:00 |
|
Ed Minnix
|
b713efb711
|
Add ThreadLocalRandom.current as another source
|
2023-12-11 11:18:38 -05:00 |
|
Ed Minnix
|
bf0123d6ae
|
Add org.apache.commons.lang.RandomStringUtils as a source
|
2023-12-11 11:18:38 -05:00 |
|
Ed Minnix
|
1daa83bf46
|
Add test cases
|
2023-12-11 11:18:38 -05:00 |
|
Ed Minnix
|
e69ff7b601
|
Move to library and add docs
|
2023-12-11 11:18:38 -05:00 |
|
Ed Minnix
|
9f986ca527
|
Add Weak Randomness Query
|
2023-12-11 11:18:38 -05:00 |
|
Ed Minnix
|
1526da5929
|
Deprecation change note
|
2023-12-08 10:50:04 -05:00 |
|
Ed Minnix
|
aebbc7d4ab
|
Add private imports to prevent compile warnings
|
2023-12-08 10:42:11 -05:00 |
|
Ed Minnix
|
1b8f3f3450
|
Deprecate or remove imports of dataflow library copies
|
2023-12-08 10:42:10 -05:00 |
|
Anders Schack-Mulligen
|
0618568cdc
|
Merge pull request #15045 from aschackmull/java/fix-cp
Java: Fix accidental cartesian product.
|
2023-12-08 15:43:01 +01:00 |
|
Anders Schack-Mulligen
|
64eb4ff753
|
Merge pull request #14983 from aschackmull/dataflow/deprecate-old-api
Data Flow: Deprecate old data flow api.
|
2023-12-08 14:27:25 +01:00 |
|
Anders Schack-Mulligen
|
7ee3068fe7
|
Java: Fix accidental cartesian product.
|
2023-12-08 13:27:05 +01:00 |
|
Ian Lynagh
|
fc11a87882
|
Kotlin: Fix dataflow with Array.set wrappers
|
2023-12-06 12:19:46 +00:00 |
|