Artem Smotrakov
1b51dd47ec
Added an example with deserialization filter to UnsafeDeserializationRmi.qhelp
2021-05-23 13:24:42 +02:00
Artem Smotrakov
c837605c85
Added test cases with sanitizers for UnsafeDeserializationRmi.ql
2021-05-23 13:01:22 +02:00
Artem Smotrakov
d2e29fc72c
Renamed RmiUnsafeDeserialization.ql -> UnsafeDeserializationRmi.ql
2021-05-23 10:21:05 +02:00
Artem Smotrakov
2d93eeae33
Covered deserialization filters in RmiUnsafeDeserialization.ql
2021-05-23 10:21:05 +02:00
Artem Smotrakov
e28f919f3d
Look for remote callable method only in RmiUnsafeDeserialization.ql
2021-05-23 10:21:05 +02:00
Artem Smotrakov
0182dfe1c0
Added RmiUnsafeDeserialization.qhelp
2021-05-23 10:21:04 +02:00
Artem Smotrakov
5ffe04d6a5
Updated expected output for RmiUnsafeDeserialization.java test
2021-05-23 10:21:04 +02:00
Artem Smotrakov
3d20330a92
More tests for RmiUnsafeDeserialization
2021-05-23 10:21:04 +02:00
Artem Smotrakov
ec6186a1c5
Draft of tests for RmiUnsafeDeserialization.ql
2021-05-23 10:21:04 +02:00
Artem Smotrakov
efa4b4f414
Cover Registry in RmiUnsafeDeserialization.ql
2021-05-23 10:21:04 +02:00
Artem Smotrakov
8b96ff9601
First draft of RmiUnsafeDeserialization.ql
2021-05-23 10:21:04 +02:00
Sebastian Bauersfeld
28f597440f
Add method invocations of Spring's SavedRequest as a remote sources.
2021-05-20 20:00:14 +07:00
luchua-bc
02aa9c6fc7
Optimize the sink and update qldoc
2021-05-18 16:12:23 +00:00
luchua-bc
d4323a4a54
Update qldoc
2021-05-18 16:12:23 +00:00
luchua-bc
9d392263a5
Refactor inconsistent method names
2021-05-18 16:12:23 +00:00
luchua-bc
2fa249a8eb
Update method name and qldoc
2021-05-18 16:12:23 +00:00
luchua-bc
2c1374bdcf
Use inline implementation for ScriptEngineFactory
2021-05-18 16:12:23 +00:00
luchua-bc
0ac8453398
Allow all arguments of methods in ScriptEngineFactory
2021-05-18 16:12:23 +00:00
luchua-bc
e4699f7fa9
Optimize the query
2021-05-18 16:12:22 +00:00
luchua-bc
d664aa6d6a
Include more scenarios and update qldoc
2021-05-18 16:12:22 +00:00
luchua-bc
852bcfb5c7
Refactor the ScriptEngine query and the Rhino code injection query into one
2021-05-18 16:12:22 +00:00
luchua-bc
b0b5338359
Rhino code injection
2021-05-18 16:12:22 +00:00
Chris Smowton
4230869ee2
Merge pull request #5819 from luchua-bc/java/jpython-injection
...
Java: CWE-094 Jython code injection
2021-05-18 16:38:40 +01:00
Chris Smowton
71f540a755
Merge pull request #5844 from haby0/SpringRedirects
...
[Java] CWE-601 Spring url redirection detect
2021-05-18 16:37:40 +01:00
luchua-bc
2a0721b2ae
Optimize the sink and update method name
2021-05-18 12:18:14 +00:00
haby0
e46de44473
Solve errors caused by private ownership
2021-05-18 19:56:32 +08:00
haby0
caf5f4d605
modified comment
2021-05-18 19:10:03 +08:00
Anders Schack-Mulligen
9b0e3b1950
Merge pull request #5814 from JLLeitschuh/feat/JLL/jackson_as_taint_step
...
[Java] Add taint tracking through Jackson deserialization
2021-05-18 09:31:16 +02:00
haby0
a0cd551bae
Add filtering of String.format
2021-05-18 11:05:10 +08:00
luchua-bc
e652d8771c
Update method name and qldoc
2021-05-17 20:36:15 +00:00
Anders Schack-Mulligen
77c93dcf26
Make private
2021-05-17 10:35:04 +02:00
luchua-bc
1497fba6f2
Remove the isAdditionalTaintStep predicate
2021-05-14 11:43:49 +00:00
Robin Neatherway
f378513ea3
Add lines-of-code tags
...
This is a proposed method for advertising which queries are measuring
the lines of code in a project in a more robust manner than inspecting
the rule id.
Note that the python "LinesOfUserCode" query should _not_ have this
property, as otherwise the results of the two queries will be summed.
2021-05-14 11:20:43 +01:00
haby0
498c99e26c
Add left value, Add return expression tracing flow
2021-05-14 16:31:59 +08:00
haby0
02e415045f
Delete RedirectBuilderFlowConfig
2021-05-13 15:48:15 +08:00
haby0
effa2b162a
Add spring url redirection detect
2021-05-13 09:55:37 +08:00
Jonathan Leitschuh
48b50f93c2
Update java/ql/src/semmle/code/java/frameworks/jackson/JacksonSerializability.qll
...
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com >
2021-05-12 08:58:01 -04:00
Sebastian Bauersfeld
bf4d88175c
Consider boxed booleans to avoid false positives for XXE.ql
2021-05-12 16:40:00 +07:00
Anders Schack-Mulligen
a247ae4357
Merge pull request #5843 from JLLeitschuh/feat/JLL/improve_kryo_support
...
[Java] Fix Kryo FP & Kryo 5 Support
2021-05-12 09:52:24 +02:00
Anders Schack-Mulligen
74ae2e0857
Merge pull request #5773 from hvitved/dataflow/aggressive-caching
...
Data flow: Cache most language-dependent predicates
2021-05-12 09:41:55 +02:00
luchua-bc
e7cd6c9972
Optimize the query
2021-05-11 16:56:12 +00:00
Jonathan Leitschuh
5a68ac88ef
Cleanup Jackson logic after code review
2021-05-11 10:48:22 -04:00
Jonathan Leitschuh
bacc3ef5b3
[Java] Jackson add support for 2 step deserialization taint flow
2021-05-11 10:36:47 -04:00
Jonathan Leitschuh
e97bad3b33
Support field access data flow for JacksonDeserializedTaintStep
2021-05-11 10:36:47 -04:00
Jonathan Leitschuh
83d527ed19
Apply suggestions from code review
...
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com >
2021-05-11 10:36:47 -04:00
Jonathan Leitschuh
d0b0b767a2
Apply suggestions from code review
...
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com >
2021-05-11 10:36:47 -04:00
Jonathan Leitschuh
d0638db6e7
[Java] Add data flow through Iterator deserializers for Jackson
2021-05-11 10:36:47 -04:00
Jonathan Leitschuh
56b1f15dda
[Java] Add taint tracking through Jackson deserialization
2021-05-11 10:36:47 -04:00
Tom Hvitved
d66506b0a3
Data flow: Rename {Argument,Parameter}NodeExt to {Arg,Param}Node
2021-05-11 14:40:10 +02:00
Anders Schack-Mulligen
744c495ac2
Merge pull request #5824 from JLLeitschuh/feat/JLL/guava_first_non_null
...
[Java] Add support for com.google.common.base.MoreObjects#firstNonNull
2021-05-11 09:42:20 +02:00