Anders Schack-Mulligen
|
f3e2bd0fd9
|
Merge pull request #3141 from pwntester/InsecureBeanValidation
Insecure Bean Validation query
|
2020-10-28 12:04:12 +01:00 |
|
Anders Schack-Mulligen
|
34ae6e0576
|
Apply suggestions from code review
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-28 09:15:08 +01:00 |
|
Alvaro Muñoz
|
77b551b693
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:12:17 +01:00 |
|
Alvaro Muñoz
|
b9c75ea462
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:12:00 +01:00 |
|
Alvaro Muñoz
|
ac116da0dc
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:11:48 +01:00 |
|
Alvaro Muñoz
|
d5b470ea0c
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:11:27 +01:00 |
|
Alvaro Muñoz
|
9785013c29
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:11:15 +01:00 |
|
Alvaro Muñoz
|
d221930c81
|
Update java/ql/src/Security/CWE/CWE-094/InsecureBeanValidation.qhelp
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:10:56 +01:00 |
|
Alvaro Muñoz
|
a9ea63b976
|
Update java/change-notes/2020-10-27-insecure-bean-validation.md
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
|
2020-10-27 21:10:46 +01:00 |
|
Alvaro Muñoz
|
1fdf0556d2
|
more fixes to make qlhelp linter happy
|
2020-10-27 17:05:00 +01:00 |
|
Alvaro Muñoz
|
aa981caea5
|
more fixes to make qlhelp linter happy
|
2020-10-27 16:32:13 +01:00 |
|
Alvaro Muñoz
|
8974f252ac
|
fix format and qlhelp errors blocking the merge
|
2020-10-27 16:19:39 +01:00 |
|
Alvaro Muñoz
|
11e57bd2f8
|
add change note for new Insecure Bean Validation query
|
2020-10-27 16:11:51 +01:00 |
|
Alvaro Muñoz
|
3378dd526e
|
remove compiled classes from stubs
|
2020-10-27 15:56:26 +01:00 |
|
Alvaro Muñoz
|
99044fc6ab
|
remove experimental query forr bean validation
|
2020-10-27 15:55:19 +01:00 |
|
Alvaro Muñoz
|
40a2007497
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2020-10-27 15:52:25 +01:00 |
|
Alvaro Muñoz
|
8b5aed2fe1
|
move md links to <a>
|
2020-10-27 15:52:25 +01:00 |
|
Alvaro Muñoz
|
8904411fe6
|
address review comments
|
2020-10-27 15:52:24 +01:00 |
|
Alvaro Muñoz
|
debfc686d1
|
Insecure Bean Validation query
|
2020-10-27 15:52:24 +01:00 |
|
Alvaro Muñoz
|
7d7933a054
|
move query out of experimental
|
2020-10-27 15:52:20 +01:00 |
|
Alvaro Muñoz
|
d990f7a470
|
move md links to <a>
|
2020-10-27 15:51:40 +01:00 |
|
Alvaro Muñoz
|
65d01f5c9e
|
address review comments
|
2020-10-27 15:51:36 +01:00 |
|
Alvaro Muñoz
|
f85778e9c7
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
6ca28a8bc6
|
move md links to <a>
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
27bd9044e7
|
address review comments
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
73fc9fda77
|
Insecure Bean Validation query
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
a36970f306
|
Add beanValidation remote source
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
3dcd8acf97
|
add expected results
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
671ea2f6c6
|
add test and stubs
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
a274a1516a
|
move source to FlowSources.qll
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
2bab9d22e9
|
move query out of experimental
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
df4164f2c0
|
Apply suggestions from code review
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
c1decf4d0d
|
move md links to <a>
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
0bf3895327
|
address review comments
|
2020-10-27 15:47:54 +01:00 |
|
Alvaro Muñoz
|
3b23cd5be3
|
Insecure Bean Validation query
|
2020-10-27 15:47:54 +01:00 |
|
Joe Farebrother
|
2050f82553
|
Merge pull request #4383 from joefarebrother/guava-strings
Java: Add modelling for Guava
|
2020-10-26 10:16:55 +00:00 |
|
Tom Hvitved
|
492b1141ef
|
Merge pull request #4445 from hvitved/csharp/sign-analysis-cfg
C#: Use CFG nodes instead of AST nodes in sign/modulus analysis
|
2020-10-26 09:45:38 +01:00 |
|
Chris Smowton
|
4fa2a79b41
|
Fix test data for WebView experimental query
|
2020-10-19 14:57:18 +01:00 |
|
Joe Farebrother
|
980fdd8dea
|
Java: Update Guava version in test stubs and change note
|
2020-10-19 11:56:28 +01:00 |
|
Joe Farebrother
|
227092e2ae
|
Java: Minor corrections to comments
Co-authored-by: Marcono1234 <Marcono1234@users.noreply.github.com>
|
2020-10-19 11:16:33 +01:00 |
|
Chris Smowton
|
3e03db178f
|
Merge pull request #4483 from smowton/smowton/admin/droid-webview-pr-rebase
Rebase of #3706
|
2020-10-19 09:29:04 +01:00 |
|
Chris Smowton
|
5a480bfb13
|
Give query an id and PathGraph query predicates
|
2020-10-16 16:19:58 +01:00 |
|
Anders Schack-Mulligen
|
a806a4f086
|
Merge pull request #4312 from JLLeitschuh/feat/JLL/java/jhipster_CVE-2019-16303
Java: QL Query Detector for JHipster Generated CVE-2019-16303
|
2020-10-16 15:47:09 +02:00 |
|
Anders Schack-Mulligen
|
b352605d12
|
Dataflow: Code review fixes.
|
2020-10-16 13:45:51 +02:00 |
|
Joe Farebrother
|
3ef9498d53
|
Java: Modify privateness of a couple imports for Guava
|
2020-10-16 12:09:39 +01:00 |
|
Anders Schack-Mulligen
|
664f04020f
|
Revert "Dataflow: Count callables instead of nodes for fieldFlowBranchLimit."
This reverts commit 1501a40de8.
|
2020-10-16 12:51:50 +02:00 |
|
Anders Schack-Mulligen
|
1501a40de8
|
Dataflow: Count callables instead of nodes for fieldFlowBranchLimit.
|
2020-10-16 12:51:17 +02:00 |
|
Anders Schack-Mulligen
|
6aae51fa4f
|
Dataflow: Sync.
|
2020-10-16 12:51:17 +02:00 |
|
Anders Schack-Mulligen
|
8f055f56b8
|
Dataflow: Adaptive field flow precision.
|
2020-10-16 12:51:17 +02:00 |
|
Anders Schack-Mulligen
|
b0f0f89dbc
|
Dataflow: Minor pruning improvements.
|
2020-10-16 12:51:17 +02:00 |
|