Erik Krogh Kristensen
|
86e97c32d6
|
fix all ql/use-string-compare
|
2022-05-17 14:11:05 +02:00 |
|
Rasmus Wriedt Larsen
|
795adf0566
|
Python: Fix API::moduleImport("foo.bar")
|
2022-05-12 13:33:00 +02:00 |
|
Rasmus Wriedt Larsen
|
cff950f5f7
|
Python: Fix select of py/insecure-cookie
|
2022-05-11 14:06:30 +02:00 |
|
Rasmus Wriedt Larsen
|
fc8633cc01
|
Python: Fix select for py/cookie-injection
|
2022-05-11 13:18:14 +02:00 |
|
Rasmus Wriedt Larsen
|
27b99c51e9
|
Python: Add placeholder precision for py/insecure-cookie
|
2022-05-11 11:36:06 +02:00 |
|
Rasmus Wriedt Larsen
|
a902d3d8f0
|
Python: Add security-severity for py/insecure-cookie
Matching the Java query
7d4767a4f5/java/ql/src/Security/CWE/CWE-614/InsecureCookie.ql (L7)
|
2022-05-11 11:34:16 +02:00 |
|
Rasmus Wriedt Larsen
|
84ad45c665
|
Python: Fix Django import
|
2022-05-11 11:33:35 +02:00 |
|
Rasmus Wriedt Larsen
|
d127d2164a
|
Merge branch 'main' into jorgectf/python/insecure-cookie
|
2022-05-11 11:13:47 +02:00 |
|
Rasmus Wriedt Larsen
|
cb17e2a649
|
Merge pull request #8595 from porcupineyhairs/pypam
Python : Add query to detect PAM authorization bypass
|
2022-05-10 13:35:12 +02:00 |
|
Rasmus Wriedt Larsen
|
2421076d2f
|
Merge pull request #8696 from RasmusWL/new-nosql-examples
Python: Improve experimental modeling for `pymongo`
|
2022-05-10 11:03:05 +02:00 |
|
Rasmus Wriedt Larsen
|
c218162104
|
Merge branch 'main' into pypam
|
2022-05-09 14:20:05 +02:00 |
|
Rasmus Wriedt Larsen
|
ab1252d196
|
Python: Add @precision high for py/pam-auth-bypass
|
2022-05-09 14:19:40 +02:00 |
|
Rasmus Wriedt Larsen
|
5f01fc24e4
|
Merge branch 'main' into promote-xxe
|
2022-05-02 11:25:55 +02:00 |
|
Rasmus Wriedt Larsen
|
3c1a37e7e1
|
Merge branch 'main' into new-nosql-examples
|
2022-05-02 11:21:36 +02:00 |
|
yoff
|
39753d5a0b
|
Merge pull request #8693 from erik-krogh/pyApi
PY: more API-graphs refactorings
|
2022-04-27 13:19:50 +02:00 |
|
Erik Krogh Kristensen
|
7dba2b5868
|
PY: revert deletion of redundant-import in ClientSuppliedIpUsedInSecurityCheckLib.qll
|
2022-04-26 14:51:21 +02:00 |
|
Erik Krogh Kristensen
|
ff73dbc35c
|
delete redundant imports
|
2022-04-22 12:55:28 +02:00 |
|
Rasmus Wriedt Larsen
|
bb6969a175
|
Merge branch 'main' into promote-xxe
|
2022-04-20 13:42:02 +02:00 |
|
Rasmus Wriedt Larsen
|
6235dc5039
|
Python: Handle find_library assignment to temp variable
|
2022-04-13 11:44:15 +02:00 |
|
Porcupiney Hairs
|
785dc1af3c
|
Include changes from review
|
2022-04-12 21:17:39 +05:30 |
|
Taus
|
ab81247b7c
|
Python: Fix modelling in ZipSlip.qll
- Remove use of points-to.
- Exclude sources and sinks in the standard library (to prevent test brittleness).
|
2022-04-08 23:19:41 +02:00 |
|
Taus
|
57beeaada0
|
Python: Fix name clash in CopyFile.qll
|
2022-04-08 23:18:03 +02:00 |
|
Taus
|
e1371151f9
|
Python: Autoformat Concepts.qll
|
2022-04-08 23:16:41 +02:00 |
|
Taus
|
8521f9a008
|
Python: Autoformat ZipSlip.ql
|
2022-04-08 23:13:38 +02:00 |
|
Taus
|
4b580820c8
|
Python: Fix broken QHelp
|
2022-04-08 23:12:46 +02:00 |
|
Rasmus Wriedt Larsen
|
ec66f26ade
|
Python: Handle get_collection on pymongo DB
|
2022-04-07 16:32:20 +02:00 |
|
Rasmus Wriedt Larsen
|
89eeaf85d5
|
Python: Handle get_database on MongoClient instance
|
2022-04-07 16:31:17 +02:00 |
|
Rasmus Wriedt Larsen
|
7ca19653df
|
Python: mongoDBInstance refactor
|
2022-04-07 16:22:57 +02:00 |
|
Rasmus Wriedt Larsen
|
e58e9a273b
|
Python: mongoClientInstance refactoring
|
2022-04-07 16:22:16 +02:00 |
|
Rasmus Wriedt Larsen
|
0ce2ced1aa
|
Python: Model pymongo.mongo_client.MongoClient
|
2022-04-07 16:22:16 +02:00 |
|
Rasmus Wriedt Larsen
|
8191be9d75
|
Python: Move last XXE/XML bomb out of experimental
|
2022-04-07 15:37:56 +02:00 |
|
Rasmus Wriedt Larsen
|
405480c410
|
Python: Rename sink definitions for XXE/XML bomb
|
2022-04-07 15:37:56 +02:00 |
|
Erik Krogh Kristensen
|
50bfc8eaa0
|
refactor uses of API::Node::getAUse() that should have been something else
|
2022-04-07 13:52:13 +02:00 |
|
Erik Krogh Kristensen
|
4e5afab082
|
refactor more python type-trackers to API-graphs
|
2022-04-07 13:51:40 +02:00 |
|
Rasmus Wriedt Larsen
|
7728b6cf1b
|
Python: Change XmlBomb vulnerability kind
|
2022-04-07 10:56:35 +02:00 |
|
Ahmed Farid
|
dfe7f532ac
|
Update CopyFile.qll
|
2022-04-05 12:42:05 +00:00 |
|
Ahmed Farid
|
0d6d07886b
|
Rename Zip.qll to CopyFile.qll
|
2022-04-05 12:37:14 +00:00 |
|
Ahmed Farid
|
8882bc1533
|
Update Frameworks.qll
|
2022-04-05 12:32:10 +00:00 |
|
Ahmed Farid
|
68bfe38529
|
Update Zip.qll
|
2022-04-05 12:31:30 +00:00 |
|
Rasmus Wriedt Larsen
|
1f285b8983
|
Python: Rename to XmlParsingVulnerabilityKind
To keep up with style guide
|
2022-04-05 11:07:12 +02:00 |
|
Rasmus Wriedt Larsen
|
ab59d5c786
|
Python: Rename to XmlParsing
To follow our style guide
|
2022-04-05 11:06:22 +02:00 |
|
Rasmus Wriedt Larsen
|
d2b03bb480
|
Python: Fix SimpleXmlRpcServer.ql
|
2022-03-31 20:37:28 +02:00 |
|
Rasmus Wriedt Larsen
|
4abab22066
|
Python: Promote XXE and XML-bomb queries
Need to write a change-note as well, but will do that tomorrow
|
2022-03-31 18:47:50 +02:00 |
|
Rasmus Wriedt Larsen
|
b8d3c5e96f
|
Python: Remove last bits of experimental XML modeling
|
2022-03-31 18:40:26 +02:00 |
|
Rasmus Wriedt Larsen
|
e11269715d
|
Python: Promote xml.sax and xml.dom.* modeling
|
2022-03-31 17:44:00 +02:00 |
|
Rasmus Wriedt Larsen
|
64aa503cc3
|
Python: Promote xml.etree modeling
|
2022-03-31 11:12:02 +02:00 |
|
Rasmus Wriedt Larsen
|
7f5f7679f8
|
Python: Promote xmltodict modeling
|
2022-03-31 10:28:34 +02:00 |
|
Rasmus Wriedt Larsen
|
80b5cde3a2
|
Python: Promote lxml parsing modeling
|
2022-03-31 10:19:08 +02:00 |
|
Rasmus Wriedt Larsen
|
1ea4bcc59f
|
Python: Make XMLParsing a Decoding subclass
|
2022-03-31 09:52:55 +02:00 |
|
Rasmus Wriedt Larsen
|
e45288e812
|
Python: => XMLParsingVulnerabilityKind
Since there are other XML vulnerabilities that are not about parsing,
this is more correct.
|
2022-03-31 09:52:55 +02:00 |
|