Tony Torralba
|
8f6d2ed2f9
|
Adjust ZipSlip query description according to review suggestions.
|
2023-06-19 10:27:41 +02:00 |
|
Tony Torralba
|
3c4d938cf1
|
Apply code review suggestions.
Co-authored-by: Asger F <asgerf@github.com>
|
2023-06-19 10:20:19 +02:00 |
|
Tony Torralba
|
3e96fe60c5
|
Go/Java/JS/Python/Ruby: Update the description and qhelp of the ZipSlip query
All filesystem operations, not just writes, with paths built from untrusted archive entry names are dangerous
|
2023-06-16 08:52:44 +02:00 |
|
erik-krogh
|
368f84785b
|
fix some more style-guide violations in the alert-messages
|
2022-10-07 11:22:22 +02:00 |
|
erik-krogh
|
aa56ca37ae
|
make the alert messages of taint-tracking queries more consistent
|
2022-09-05 14:04:52 +02:00 |
|
erik-krogh
|
3553f3d9b8
|
update {rb/py/js/go}/path-injection to match java/csharp
|
2022-08-22 21:41:45 +02:00 |
|
erik-krogh
|
594fbc678e
|
update js/zip-slip to match java/go/csharp
|
2022-08-22 21:41:45 +02:00 |
|
Asger Feldthaus
|
f6da030572
|
JS: Migrate to *Query.qll convention
|
2021-08-12 09:30:18 +02:00 |
|
Calum Grant
|
771e686946
|
Update security-severity scores
|
2021-06-15 13:25:17 +01:00 |
|
Calum Grant
|
a594afb828
|
Add security-severity metadata
|
2021-06-10 20:11:08 +01:00 |
|
Chris Smowton
|
578ea1ae43
|
Fix OWASP broken links
|
2020-10-01 13:09:52 +01:00 |
|
Max Schaefer
|
020d31c3b6
|
JavaScript: Fix inconisstency in TaintedPath.qhelp.
|
2019-08-12 10:29:41 +01:00 |
|
Max Schaefer
|
cc8d68082e
|
JavaScript: Show ZipSlip results by default.
|
2019-03-14 08:50:47 +00:00 |
|
Jason Reed
|
c1b218a5ff
|
JS: Documentation fixes
|
2019-02-28 15:46:19 -05:00 |
|
Jason Reed
|
c5e57dacf8
|
JS: Actually use fileName in examples
|
2019-02-28 15:46:14 -05:00 |
|
Jason Reed
|
674d2790b4
|
JS: Address review comments
|
2019-02-28 15:46:07 -05:00 |
|
Jason Reed
|
caebdd2f68
|
JS: Fix incorrect sample link
|
2019-02-28 15:46:00 -05:00 |
|
Jason Reed
|
2fc2a393b7
|
JS: Address review comments
|
2019-02-28 15:45:52 -05:00 |
|
Jason Reed
|
32d48ba98b
|
JS: Run auto-formatter
|
2019-02-28 15:45:20 -05:00 |
|
Jason Reed
|
abd2644af7
|
JS: Address review comments
|
2019-02-28 15:45:13 -05:00 |
|
Jason Reed
|
baa4f08259
|
JS: Add new query for ZipSlip (CWE-022)
|
2019-02-28 15:45:08 -05:00 |
|
Max Schaefer
|
31bb39a810
|
JavaScript: Autoformat all QL files.
|
2019-01-07 10:15:45 +00:00 |
|
Max Schaefer
|
3fcd02ab0e
|
JavaScript: Rename hasPathFlow to hasFlowPath for consistency with other languages.
|
2018-11-14 11:23:17 +00:00 |
|
Max Schaefer
|
52ae757279
|
JavaScript: Select Nodes (instead of PathNodes) everywhere.
|
2018-11-14 09:16:40 +00:00 |
|
Max Schaefer
|
e365b722ee
|
JavaScript: Select source and sink in all path queries.
|
2018-11-14 09:16:40 +00:00 |
|
Max Schaefer
|
11d6259dbf
|
JavaScript: Move from Node to PathNode.
|
2018-11-14 09:16:40 +00:00 |
|
Max Schaefer
|
8d87f556e1
|
JavaScript: Add import DataFlow::PathGraph.
|
2018-11-14 09:16:40 +00:00 |
|
Max Schaefer
|
60a1357092
|
JavaScript: Make all taint-based security queries have @kind path-problem.
|
2018-11-14 09:16:40 +00:00 |
|
Max Schaefer
|
c51cd50133
|
JavaScript: Remove a few unnecessary imports.
|
2018-11-14 09:16:40 +00:00 |
|
Pavel Avgustinov
|
b55526aa58
|
QL code and tests for C#/C++/JavaScript.
|
2018-08-02 17:53:23 +01:00 |
|