Erik Krogh Kristensen
|
69353bb014
|
patch upper-case acronyms to be PascalCase
|
2022-03-11 11:10:33 +01:00 |
|
Erik Krogh Kristensen
|
4734f1916e
|
Merge pull request #7598 from erik-krogh/fieldOnlyUsedInCharPred
QL: field only used in charPred
|
2022-03-08 11:25:57 +01:00 |
|
CodeQL CI
|
62ee8fce3a
|
Merge pull request #8186 from asgerf/js/request-forgery-docs-followup
Approved by esbena, hubwriter
|
2022-02-23 11:46:37 +00:00 |
|
Stephan Brandauer
|
a664e02d04
|
Merge pull request #8014 from kaeluka/js/functionality-from-untrusted-source
JS: Functionality from untrusted sources query (CWE-830)
|
2022-02-23 12:45:31 +01:00 |
|
Stephan Brandauer
|
1ed71e15f3
|
apply docreview feedback
|
2022-02-23 11:21:22 +01:00 |
|
Asger Feldthaus
|
22ba43fff6
|
JS: Minor fixup in the client-side request forgery qhelp
|
2022-02-23 10:54:26 +01:00 |
|
Stephan Brandauer
|
c17d8b145a
|
Merge pull request #8054 from asgerf/js/split-request-forgery
JS: split request forgery query into server-side and client-side variants
|
2022-02-23 10:27:16 +01:00 |
|
Erik Krogh Kristensen
|
73f2e89f3e
|
Merge pull request #8165 from erik-krogh/protoWrite
JS: support more property writes in js/prototype-pollution-utility
|
2022-02-22 21:30:22 +01:00 |
|
Erik Krogh Kristensen
|
517e17d422
|
support more property writes in js/prototype-pollution-utility, and generalize ObjectDefinePropertyAsPropWrite
|
2022-02-22 13:23:34 +01:00 |
|
Stephan Brandauer
|
2278e7f6e6
|
CWE 830 polish error messages
|
2022-02-22 11:41:54 +01:00 |
|
Stephan Brandauer
|
82330391c3
|
CWE-830 add support for setting attributes via setAttribute method
|
2022-02-22 11:41:54 +01:00 |
|
Stephan Brandauer
|
d80cd1aeb5
|
CWE 830 test where both branches in a ternary are unsafe
|
2022-02-22 11:41:53 +01:00 |
|
Stephan Brandauer
|
2934aa1a3a
|
rewrite docs, improve error messages, etc
|
2022-02-22 11:41:53 +01:00 |
|
Stephan Brandauer
|
d2335b65d5
|
stylistic improvements after review
|
2022-02-22 11:41:53 +01:00 |
|
Stephan Brandauer
|
9aec4437e2
|
polish qhelp for CWE-830 and add test file
|
2022-02-22 11:41:53 +01:00 |
|
Stephan Brandauer
|
44d86569ac
|
remove illegal chars from comments
|
2022-02-22 11:41:53 +01:00 |
|
Stephan Brandauer
|
fd77e27ed9
|
replace taint tracking by type tracking and merge remaining queries for CWE-830
|
2022-02-22 11:41:53 +01:00 |
|
Stephan Brandauer
|
8cafa6d562
|
improve error message in CWE-830
|
2022-02-22 11:41:53 +01:00 |
|
Stephan Brandauer
|
780fa97869
|
always require integrity checking for certain CDNs
|
2022-02-22 11:41:53 +01:00 |
|
Stephan Brandauer
|
8d397fea09
|
JS: query to find dynamic creations of DOM elements that use untrusted sources
|
2022-02-22 11:41:52 +01:00 |
|
Stephan Brandauer
|
b35c70994f
|
permit http urls to 127.0.0.1 and others
|
2022-02-22 11:41:52 +01:00 |
|
Stephan Brandauer
|
dd2b779a3c
|
add CWE 830 link to references
|
2022-02-22 11:41:52 +01:00 |
|
Stephan Brandauer
|
6722c17bb0
|
JS: Functionality from untrusted sources query (CWE-830)
|
2022-02-22 11:41:52 +01:00 |
|
Erik Krogh Kristensen
|
1407b49a8f
|
fix some instances of ql/pred-doc-style for JS
|
2022-02-21 15:02:21 +01:00 |
|
Asger Feldthaus
|
69995d5750
|
Shared: rephrase request forgery name and description
|
2022-02-17 09:07:08 +01:00 |
|
Asger Feldthaus
|
3496ae131b
|
JS: Factor out <recommendation> part of qhelp
|
2022-02-17 09:07:08 +01:00 |
|
Asger Feldthaus
|
8ac0ec8dfc
|
JS: Write help for ClientSideRequestForgery
|
2022-02-16 18:33:31 +01:00 |
|
Asger Feldthaus
|
91c64152d2
|
JS: Rephrase the qhelp for SSRF query
|
2022-02-16 13:35:01 +01:00 |
|
Asger Feldthaus
|
260638c68b
|
JS: Add ClientSideRequestForgery and split request-forgery results between the two
|
2022-02-16 13:35:01 +01:00 |
|
Esben Sparre Andreasen
|
816d79692b
|
ignore deliberately hardcoded password strings
|
2022-02-16 09:47:01 +01:00 |
|
Asger Feldthaus
|
f7108506f2
|
JS: Raise precision tag of js/request-forgery
|
2022-02-14 14:20:41 +01:00 |
|
Ethan Palm
|
2f7f9d9032
|
Move explanation of example above sample code
|
2022-02-09 10:45:24 -08:00 |
|
Erik Krogh Kristensen
|
aa95dd4ec7
|
fix typo
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2022-02-08 00:19:40 +01:00 |
|
Erik Krogh Kristensen
|
6f28cb9201
|
lower the precision of js/unsafe-code-construction
|
2022-02-07 13:35:29 +01:00 |
|
Erik Krogh Kristensen
|
eb133f59f6
|
update qhelp to focus on properly documenting potentially unsafe library functions
|
2022-02-07 13:34:18 +01:00 |
|
Erik Krogh Kristensen
|
d77c28f6a7
|
add qhelp for unsafe-code-construction
|
2022-02-07 13:34:18 +01:00 |
|
Erik Krogh Kristensen
|
198a464346
|
add js/unsafe-code-construction query
|
2022-02-07 13:34:18 +01:00 |
|
Naman Jain
|
aea7054938
|
modified query and added tests
|
2022-02-02 19:39:08 +05:30 |
|
Erik Krogh Kristensen
|
0f85a52f09
|
Merge pull request #7773 from erik-krogh/CWE-367
JS: add a js/file-system-race query
|
2022-02-01 15:36:13 +01:00 |
|
Erik Krogh Kristensen
|
a51f892a99
|
move dot in qhelp
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2022-02-01 14:34:30 +01:00 |
|
Erik Krogh Kristensen
|
e6c90670e6
|
Merge pull request #7740 from erik-krogh/CWE-347
JS: promote the js/jwt-missing-verification query out of experimental
|
2022-02-01 13:10:35 +01:00 |
|
Erik Krogh Kristensen
|
8dcec2e037
|
apply suggestions from doc review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-01-31 13:17:26 +01:00 |
|
Erik Krogh Kristensen
|
ec1a8cc826
|
apply suggestions from doc review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-01-31 12:32:12 +01:00 |
|
Erik Krogh Kristensen
|
7aa59ca233
|
Merge pull request #7633 from erik-krogh/CWE-300
JS: add js/http-dependency query
|
2022-01-28 12:10:14 +01:00 |
|
Erik Krogh Kristensen
|
b5198bdaca
|
apply suggestions from doc review
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
|
2022-01-28 10:46:27 +01:00 |
|
Erik Krogh Kristensen
|
bf9bcc9600
|
add a js/file-system-race query
|
2022-01-28 09:41:12 +01:00 |
|
Erik Krogh Kristensen
|
179c26da9a
|
apply suggestions from review
|
2022-01-28 09:37:46 +01:00 |
|
Erik Krogh Kristensen
|
e75dc2116f
|
add CWE-184 to incomplete-scheme-check and bad-tag-filter
|
2022-01-26 16:13:13 +01:00 |
|
Erik Krogh Kristensen
|
abd87615ff
|
update qhelp with suggestions
Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
|
2022-01-26 11:03:05 +01:00 |
|
Erik Krogh Kristensen
|
de633940fe
|
promote the js/jwt-missing-verification query out of exeprimental
|
2022-01-26 09:35:54 +01:00 |
|