Alex Ford
|
a893911dba
|
Ruby: Use a newtype instead of DataFlow::FlowState for insecure-download
|
2023-09-07 14:22:18 +01:00 |
|
Alex Ford
|
75fdde543f
|
Ruby: Use a newtype instead of DataFlow::FlowState for hardcoded-data
|
2023-09-07 14:13:26 +01:00 |
|
Alex Ford
|
0d7d5a35c9
|
Ruby: Use a newtype instead of DataFlow::FlowState for code-injection
|
2023-09-07 13:39:10 +01:00 |
|
Alex Ford
|
dfc3b33910
|
Ruby: Use a newtype instead of DataFlow::FlowState for unicode-bypass-validation
|
2023-09-07 12:09:47 +01:00 |
|
Alex Ford
|
98851736d6
|
Revert "Ruby: configsig rb/tainted-format-string"
This reverts commit f5860cb4818dc3c07eeb6731e75bf5df203dd48f.
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
bf6837cca0
|
Revert "Ruby: configsig rb/http-to-file-access"
This reverts commit e77ba1589663905c952cdb643ab66885760b27bd.
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
e399eac2b3
|
Ruby: changenote for using new dataflow api
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
73ed5696f3
|
Ruby: configsig rb/xxe
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
956207b7d9
|
Ruby: configsig rb/meta/tainted-nodes
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
f24102e0e7
|
Ruby: configsig rb/weak-params
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
6c06def5d7
|
Ruby: configsig rb/manually-checking-http-verb
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
39af2d2870
|
Ruby: configsig rb/user-controlled-file-decompression
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
cdc788b162
|
Ruby: configsig rb/hardcoded-credentials
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
4d1684e37b
|
Ruby: configsig rb/overly-permissive-file
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
b6d12f8b1c
|
Ruby: configsig rb/zip-slip
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
ebf2a2e1f5
|
Ruby: configsig rb/unicode-bypass-validation
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
7445fc43f9
|
Ruby: configsig rb/regexp-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
494b7b3fdf
|
Ruby: configsig rb/polynomial-redos
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
04d3d04317
|
Ruby: configsig rb/regex/badly-anchored-regexp
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
77f3a70376
|
Ruby: renames for rb/xpath-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
42cd58695d
|
Ruby: configsig rb/url-redirection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
f79796a644
|
Ruby: configsig rb/shell-command-constructed-from-input
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
f03f670312
|
Ruby: configsig rb/html-constructed-from-input
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
8ad6c72ba2
|
Ruby: configsig rb/unsafe-deserialization
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
461bc0d359
|
Ruby: configsig rb/unsafe-code-construction
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
3e23a6e021
|
Ruby: configsig rb/server-side-template-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
0a73ebdbee
|
Ruby: configsig rb/tainted-format-string
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
f5e433940f
|
Ruby: renames for rb/stored-xss
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
030aae5693
|
Ruby: configsig rb/stack-trace-exposure
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
bf1cb33be3
|
Ruby: configsig rb/sql-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
ba8ff0710d
|
Ruby: configsig rb/request-forgery
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
df9173502e
|
Ruby: configsig rb/sensitive-get-query
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
593d9a48d4
|
Ruby: configsig rb/reflected-xss
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
ad2bbfb265
|
Ruby: configsig rb/path-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
867e47bcdd
|
Ruby: renames for rb/log-injection
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
eb34bbbfd2
|
Ruby: renames for rb/ldap-injection
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
d46eceb5f4
|
Ruby: configsig rb/kernel-open
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
a8ad0d8ff5
|
Ruby: renames for rb/insecure-download
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
c973fc1274
|
Ruby: configsig rb/http-to-file-access
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
2536f1a0cd
|
Ruby: configsig rb/user-controlled-bypass
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
377570f361
|
Ruby: configsig rb/command-line-injection
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
b1a49ddb0d
|
Ruby: configsig rb/code-injection
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
6fa267a820
|
Ruby: configsig rb/clear-text-storage-sensitive-data
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
2a2f21d3a9
|
Ruby: configsig rb/clear-text-logging-sensitive-data
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
ce35d6921f
|
Ruby: configsig rb/hardcoded-data-interpreted-as-code
|
2023-08-31 16:20:18 +01:00 |
|
Harry Maclean
|
54c2221f35
|
Merge pull request #14033 from hmac/excon-bugfix
Ruby: Fix bug in excon model
|
2023-08-23 14:24:53 +01:00 |
|
Harry Maclean
|
d18ca3f5d7
|
Ruby: Fix bug in excon model
If a codebase included a definition for `Excon.new`, we matched
connection nodes to unrelated request nodes.
|
2023-08-23 12:55:36 +01:00 |
|
Harry Maclean
|
842da58269
|
Ruby: Update test fixture
|
2023-08-23 09:59:04 +01:00 |
|
Harry Maclean
|
fb4b774c0d
|
Merge pull request #13967 from hmac/remove-splat-all
Ruby: Remove isSplatAll
|
2023-08-23 09:40:06 +01:00 |
|
Tom Hvitved
|
5192d7c137
|
Merge pull request #13997 from hvitved/ruby/type-tracking-splats
Ruby: Include more (hash) splat flow in type tracking
|
2023-08-22 11:33:39 +02:00 |
|