Napalys
|
875478c1c6
|
JS: Fixed path query not flagging new RegExp with DotRemovingReplaceCall
|
2024-11-28 11:26:45 +01:00 |
|
Napalys
|
aa557cf950
|
JS: Added tests for DotRemovingReplaceCall with RegExp Object.
|
2024-11-28 11:26:44 +01:00 |
|
Napalys
|
23b18aeca9
|
JS: Now unknown flags are not flagged in taint paths
|
2024-11-28 11:26:41 +01:00 |
|
Napalys
|
7db6f7c721
|
JS: Added test cases with new RegExp for Tainted paths, currently works only with literals
|
2024-11-28 11:26:39 +01:00 |
|
Napalys
|
b239bfabf1
|
Added tests forIncompleteHostnameRegExp and normalizedPaths using matchAll
|
2024-11-05 09:22:26 +01:00 |
|
Asger F
|
7a7ab457a9
|
JS: Delete unneeded test code (and shift line numbers)
|
2024-08-16 14:38:54 +02:00 |
|
Asger F
|
9ee7599aeb
|
JS: Move AngularJSTemplateUrlSink to ClientSideUrlRedirection query
This is not perfect but at least we can be consistent about keeping URLs-that-lead-to-xss in the same query
|
2024-08-16 14:37:13 +02:00 |
|
Max Schaefer
|
dfffa1e237
|
Apply suggestions from code review
Co-authored-by: Sam Browning <106113886+sabrowning1@users.noreply.github.com>
|
2023-11-21 10:07:11 +00:00 |
|
Max Schaefer
|
d147faba4e
|
Update qhelp for js/path-injection.
|
2023-11-20 11:58:00 +00:00 |
|
Asger F
|
27085b1fd0
|
JS: Fix whitespace
|
2023-07-10 12:07:13 +02:00 |
|
Asger F
|
fe90146a16
|
JS: Add test for path.join with spread argument
|
2023-07-10 12:07:07 +02:00 |
|
Asger F
|
06bc0f6957
|
JS: Add test for fs/promises
|
2023-07-10 12:05:03 +02:00 |
|
erik-krogh
|
368f84785b
|
fix some more style-guide violations in the alert-messages
|
2022-10-07 11:22:22 +02:00 |
|
erik-krogh
|
aa56ca37ae
|
make the alert messages of taint-tracking queries more consistent
|
2022-09-05 14:04:52 +02:00 |
|
erik-krogh
|
7e0bd5bde4
|
update expected output of tests
|
2022-08-22 21:41:47 +02:00 |
|
Erik Krogh Kristensen
|
7cef4322e7
|
add model for chownr
|
2022-06-29 22:09:23 +02:00 |
|
Stephan Brandauer
|
fb66ccff39
|
handlebars taint step: conservatively assume unknown templates have no flow to helpers
|
2022-04-13 09:27:59 +02:00 |
|
Stephan Brandauer
|
9c3fcb6268
|
precise tracking of handlebars arguments
|
2022-03-28 17:26:43 +02:00 |
|
Stephan Brandauer
|
a28e9c5b6e
|
documentation for handlebars.js flow step
|
2022-03-24 13:08:52 +01:00 |
|
Stephan Brandauer
|
0bd9e9f298
|
add handlebars taint step
|
2022-03-24 11:46:16 +01:00 |
|
Erik Krogh Kristensen
|
b59c7911a3
|
update locations of expected output
|
2022-02-07 15:23:26 +01:00 |
|
Erik Krogh Kristensen
|
ca5f91e587
|
recognize more startswith sanitizers for path-injection queries
|
2022-02-07 14:19:13 +01:00 |
|
Erik Krogh Kristensen
|
edcb3ba902
|
add file sources from jszip to js/zip-slip
|
2022-02-04 14:39:49 +01:00 |
|
Stephan Brandauer
|
4ee290acd3
|
update test for 'node:' prefix
|
2022-01-25 14:25:44 +01:00 |
|
Stephan Brandauer
|
20ea825e4a
|
test for 'node:' prefix for importing node modules
|
2022-01-25 13:43:16 +01:00 |
|
Esben Sparre Andreasen
|
9ffc02944d
|
add file write model for express-fileupload mv
|
2021-12-10 15:05:34 +01:00 |
|
Asger Feldthaus
|
f14f9449ee
|
JS: Use getAMatchedString instead of getConstantString
|
2021-11-08 15:35:35 +01:00 |
|
Asger Feldthaus
|
b3e64f1669
|
JS: Add test
|
2021-11-08 15:32:43 +01:00 |
|
Asger Feldthaus
|
5f4c1dd19b
|
JS: Support regexp-based path traversal check
|
2021-11-02 14:12:05 +01:00 |
|
Asger Feldthaus
|
83edcf515b
|
JS: Add test for regexp-based sanitizer
|
2021-11-02 14:12:04 +01:00 |
|
Erik Krogh Kristensen
|
32ac8778bd
|
add the cwd option to shell executions as a sink to js/path-injection
|
2021-08-23 07:32:05 +02:00 |
|
Asger Feldthaus
|
cb0075f15a
|
JS: Remove use of deprecated API
|
2021-08-12 09:30:43 +02:00 |
|
CodeQL CI
|
a02a82caac
|
Merge pull request #6284 from erik-krogh/qs
Approved by asgerf
|
2021-07-16 02:11:59 -07:00 |
|
Erik Krogh Kristensen
|
14b26f2a68
|
add mkdirp as a sink for tainted-path
|
2021-07-14 19:32:22 +02:00 |
|
Erik Krogh Kristensen
|
f462c9bb76
|
add taint through the parseqs library
|
2021-07-14 17:22:35 +02:00 |
|
Erik Krogh Kristensen
|
bec1818fc7
|
add taint through the normalize-url library
|
2021-07-14 17:15:14 +02:00 |
|
Erik Krogh Kristensen
|
193ddfc771
|
add taint through the qs library
|
2021-07-14 16:56:51 +02:00 |
|
CodeQL CI
|
436168aa4f
|
Merge pull request #6267 from erik-krogh/read-pkg
Approved by asgerf
|
2021-07-14 01:01:33 -07:00 |
|
Erik Krogh Kristensen
|
07bc5856db
|
add the cwd option from read-pkg as sink for path-injection
|
2021-07-12 23:43:15 +02:00 |
|
Erik Krogh Kristensen
|
899e54fbc9
|
add support for the slash library
|
2021-07-12 16:36:54 +02:00 |
|
Erik Krogh Kristensen
|
4360e5dcbc
|
add model of the thenify library
|
2021-06-22 11:55:58 +02:00 |
|
Erik Krogh Kristensen
|
61cc415a32
|
add model of the util.promisify library
|
2021-06-22 11:55:58 +02:00 |
|
Erik Krogh Kristensen
|
2f3ea4412f
|
add model of the pify library
|
2021-06-22 11:55:54 +02:00 |
|
CodeQL CI
|
169e67cbb8
|
Merge pull request #5990 from erik-krogh/prettier
Approved by asgerf
|
2021-06-08 12:17:24 -07:00 |
|
Erik Krogh Kristensen
|
5961dd1459
|
add another test for the resolve library
|
2021-06-06 22:54:12 +02:00 |
|
Erik Krogh Kristensen
|
dd2fe2a489
|
add the resolve library as a sink to js/path-injection
|
2021-06-06 22:04:32 +02:00 |
|
Erik Krogh Kristensen
|
788c5ba701
|
add support for the prettier API
|
2021-06-02 15:33:08 +02:00 |
|
Erik Krogh Kristensen
|
3b82452d76
|
detect fs modules that pass through a reduce call
|
2021-03-25 14:47:43 +01:00 |
|
Erik Krogh Kristensen
|
2f3869f41b
|
add model for puppeteer
|
2021-03-17 10:03:51 +01:00 |
|
Erik Krogh Kristensen
|
d95d427c5b
|
better support for the &&=, ||=, and ??= operators
|
2020-08-13 09:22:32 +02:00 |
|