Chris Smowton
|
f006cd0e37
|
Merge pull request #8360 from JLLeitschuh/feat/JLL/compile_time_constant_getStringified
[Java] Add CompileTimeConstantExpr.getStringified method
|
2022-03-11 10:34:52 +00:00 |
|
Erik Krogh Kristensen
|
69353bb014
|
patch upper-case acronyms to be PascalCase
|
2022-03-11 11:10:33 +01:00 |
|
Jonathan Leitschuh
|
363fff2358
|
Cleanup from code review feedback
|
2022-03-09 10:48:06 -05:00 |
|
Taus
|
7b877fb317
|
Merge pull request #8336 from tausbn/python-fix-a-bunch-of-ql-warnings
Python: Fix a bunch of QL warnings
|
2022-03-09 16:31:28 +01:00 |
|
Taus
|
063a8bbc43
|
Python: Apply suggestions from code review
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2022-03-08 15:20:35 +01:00 |
|
Jonathan Leitschuh
|
2e8b5f743b
|
[Java] Add CompileTimeConstantExpr.getStringified method
Removes CharacterLiteral from CompileTimeConstantExpr.getStringValue
Resolves:
- https://github.com/github/codeql/pull/8325#issuecomment-1060470279
- https://github.com/github/codeql/pull/8325#issuecomment-1060587205
|
2022-03-07 20:11:38 -05:00 |
|
Jonathan Leitschuh
|
a21992ade9
|
Minor refactoring to improve tests and documentation
|
2022-03-07 18:40:53 -05:00 |
|
Jonathan Leitschuh
|
5b651f29d8
|
Fix insufficient tests and add documentation
|
2022-03-07 16:39:40 -05:00 |
|
Taus
|
af7f532212
|
Python: Fix up a bunch of function QLDoc
|
2022-03-07 18:59:49 +00:00 |
|
Jonathan Leitschuh
|
38897f2ec1
|
Fixup tests from code review changes
|
2022-03-04 09:33:51 -05:00 |
|
Jonathan Leitschuh
|
17b6e66814
|
Apply suggestions from code review
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com>
|
2022-03-04 09:29:57 -05:00 |
|
Jonathan Leitschuh
|
7ab193dde2
|
Add System.getProperties().getProperty support
|
2022-03-03 20:08:38 -05:00 |
|
Jonathan Leitschuh
|
04cd0dbfe9
|
[Java] Add CharacterLiteral to CompileTimeConstantExpr.getStringValue
|
2022-03-03 18:08:17 -05:00 |
|
Jonathan Leitschuh
|
31527a67e5
|
Refactor OS Checks & SystemProperty logic from review feedback
|
2022-03-03 17:15:35 -05:00 |
|
Jonathan Leitschuh
|
a7adbb7291
|
Refactor more system property access logic
|
2022-03-02 19:33:05 -05:00 |
|
Jonathan Leitschuh
|
3c53a05e16
|
Add OS Checks based upon separator or path separator
|
2022-03-02 14:15:56 -05:00 |
|
Jonathan Leitschuh
|
dad9a02fbd
|
Update TempDirInfoDisclosure with new OS Guards
|
2022-03-02 12:51:15 -05:00 |
|
Jonathan Leitschuh
|
5913c9acad
|
Refactor OS Guard Checks
|
2022-03-02 12:51:14 -05:00 |
|
Jonathan Leitschuh
|
fd63107edf
|
Update OS Check from Review Feedback
|
2022-03-02 12:51:12 -05:00 |
|
Jonathan Leitschuh
|
9f5022ee95
|
Review fixup and add test for apache SystemUtils
|
2022-03-02 12:50:38 -05:00 |
|
Jonathan Leitschuh
|
39828fd596
|
Apply OS guard checks to TempDirLocalInformationDisclosure
|
2022-03-02 12:50:37 -05:00 |
|
Jonathan Leitschuh
|
cd073a2173
|
Java: Add Guard Classes for checking OS
|
2022-03-02 12:50:35 -05:00 |
|
Michael Nebel
|
24640c3670
|
Java: Make a testcase for wrappers of sources.
|
2022-02-28 16:57:36 +01:00 |
|
Anders Schack-Mulligen
|
908cc40c9f
|
Java: Fix bug in model flow sanitizer.
|
2022-02-28 16:48:23 +01:00 |
|
luchua-bc
|
88d9694628
|
Query to detect insecure WebResourceResponse implementation
|
2022-02-26 02:03:35 +00:00 |
|
Chris Smowton
|
f981fee37d
|
Adjust test expectation
|
2022-02-25 20:05:06 +00:00 |
|
Chris Smowton
|
8fbd8c52dd
|
Fix test expectations
|
2022-02-25 17:35:52 +00:00 |
|
Chris Smowton
|
e02a3d0ddd
|
Rename qlref file
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
3a2d514b18
|
Create ComparingValueOfSensetiveHeader.qlref
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
0d278f6d61
|
Create Test.java
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
1bc5fe13eb
|
Update and rename java/ql/test/experimental/query-tests/security/CWE-208/TimingAttackAgainstHeader.expected to java/ql/test/experimental/query-tests/security/CWE-208/TimingAttackAgainstHeader/TimingAttackAgainstHeader.expected
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
63133f7e8b
|
Update TimingAttackAgainstHeader.expected
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
f2457dafb5
|
Create TimingAttackAgainstHeader.expected
|
2022-02-25 17:33:08 +00:00 |
|
Chris Smowton
|
091227982c
|
Delete unnecessary test files
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
19d0e1f4a7
|
Create ComparingValueOfSensetiveHeader.qlref
|
2022-02-25 17:33:07 +00:00 |
|
ahmed532009
|
a0a1c587e5
|
Create ComparingValueOfSensetiveHeader.java
|
2022-02-25 17:33:07 +00:00 |
|
Chris Smowton
|
b1c98ae3c2
|
Add further test directly examining signature of method with problematic parameter types
|
2022-02-24 17:39:11 +00:00 |
|
Chris Smowton
|
379f2438a6
|
Add test checking that inheritence is noticed even with annotations present
|
2022-02-24 17:39:11 +00:00 |
|
Chris Smowton
|
7b425a80bc
|
Note path query expectations
|
2022-02-23 16:02:54 +00:00 |
|
Chris Smowton
|
476997a599
|
Replace more non-breaking spaces
|
2022-02-23 11:02:17 +00:00 |
|
Porcupiney Hairs
|
c81d85f321
|
Include suggestions from review
|
2022-02-22 23:07:34 +05:30 |
|
Porcuiney Hairs
|
e536628a66
|
Java : Add SSTI query
|
2022-02-22 15:57:53 +05:30 |
|
Asger Feldthaus
|
a121b73181
|
Java: update CSV rows to dot-separated syntax
|
2022-02-21 08:16:55 +01:00 |
|
Asger Feldthaus
|
7f808710ec
|
Java: update model generator
|
2022-02-21 08:16:54 +01:00 |
|
Tony Torralba
|
111aabb707
|
Merge pull request #7712 from luchua-bc/java/file-path-injection
Java: CWE-073 File path injection with the JFinal framework
|
2022-02-16 12:01:34 +01:00 |
|
Tony Torralba
|
5f0ab522f3
|
Merge pull request #7988 from Marcono1234/marcono1234/sealed-types-predicates
Java: Add predicates for sealed classes
|
2022-02-15 15:11:56 +01:00 |
|
luchua-bc
|
fd533f2ba8
|
Remove the same callable constraint
|
2022-02-15 12:44:23 +00:00 |
|
Marcono1234
|
a496b1d1a1
|
Java: Add predicates for sealed classes
|
2022-02-14 21:04:38 +01:00 |
|
Chris Smowton
|
0bf6c83ef2
|
Merge pull request #4388 from JLLeitschuh/feat/JLL/java/CWE-200_temp_directory_local_information_disclosure
Java: CWE-200: Temp directory local information disclosure vulnerability
|
2022-02-14 18:58:44 +00:00 |
|
Chris Smowton
|
fd4dc95d84
|
Merge pull request #6443 from artem-smotrakov/ignored-hostname-verifier
Java: An experimental query for ignored hostname verification
|
2022-02-14 18:56:27 +00:00 |
|