Tamas Vajk
|
e08b629cb5
|
Add documentation for URL opening sinks
|
2021-04-27 10:32:41 +02:00 |
|
Tamás Vajk
|
cb28bc80b7
|
Merge branch 'main' into feature/java-sinks-csv
|
2021-04-22 11:41:18 +02:00 |
|
Tamas Vajk
|
7134eb9079
|
Improve documentation of csv sink models
|
2021-04-22 11:37:41 +02:00 |
|
Tamas Vajk
|
1caa5c4780
|
Adjust hostname verifier sink identifier name
|
2021-04-22 11:22:18 +02:00 |
|
Tamas Vajk
|
6c78a247f2
|
Revert erroneous refactoring in header splitting sink base class
|
2021-04-22 11:20:39 +02:00 |
|
Tamas Vajk
|
9b1c54e81b
|
Add argument indices to HTTP header splitting sinks
|
2021-04-22 11:17:25 +02:00 |
|
Tamas Vajk
|
180904e9f6
|
Revert "Java: Convert Google HTTP client API parseAs sink to CSV format"
This reverts commit 3e53484bb3.
|
2021-04-22 11:14:51 +02:00 |
|
Owen Mansel-Chan
|
fea9f5f431
|
Merge pull request #5746 from owen-mc/java/refactor-exec-tainted
Make ExecTainted easier to extend
|
2021-04-22 10:14:28 +01:00 |
|
Owen Mansel-Chan
|
8a01799fb8
|
Make imports private
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
|
2021-04-22 09:46:49 +01:00 |
|
Owen Mansel-Chan
|
4b8d4f5bbd
|
Update docs
|
2021-04-22 09:30:50 +01:00 |
|
Owen Mansel-Chan
|
e448dcb725
|
Avoid bad join order
We want to avoid joining on `i` first.
|
2021-04-22 09:30:49 +01:00 |
|
Owen Mansel-Chan
|
9f1704560b
|
Include constructors in abstract class
|
2021-04-22 09:30:48 +01:00 |
|
Chris Smowton
|
94f0a1532d
|
Merge pull request #5682 from smowton/smowton/docs/fix-has-modifier-comment
Fix documentation of Modifier.qll
|
2021-04-21 15:41:29 +01:00 |
|
Owen Mansel-Chan
|
9c72e73a82
|
Make ExecTainted easier to extend
To add a method that executes a command, you can now define a class
extending ExecMethod.
|
2021-04-21 14:55:37 +01:00 |
|
Anders Schack-Mulligen
|
9362ae0687
|
Merge pull request #5422 from tamasvajk/feature/sink-migration-ldap
Java: Migrate LDAP injection sinks to CSV format
|
2021-04-21 10:05:28 +02:00 |
|
yo-h
|
00137f2905
|
Merge pull request #5721 from github/yo-h/java-diagnostic-queries
Java: add extractor `diagnostic` queries
|
2021-04-20 13:36:49 -04:00 |
|
Tamas Vajk
|
583513bafd
|
Fix review findings
|
2021-04-20 16:28:47 +02:00 |
|
Chris Smowton
|
9bfb0d93ca
|
Autoformat QL
|
2021-04-20 13:59:09 +01:00 |
|
Chris Smowton
|
0ec3ee29e4
|
Style last use of SecureASTCustomizer
|
2021-04-20 12:44:49 +01:00 |
|
Hayk Andriasyan
|
bb58a50503
|
Update GroovyInjection.qhelp
|
2021-04-20 15:41:58 +04:00 |
|
p0wn4j
|
f2de440886
|
[Java] CWE-094: Query to detect Groovy Code Injections
|
2021-04-20 19:18:24 +04:00 |
|
yo-h
|
87cd72496c
|
Java: add extractor diagnostic queries
|
2021-04-19 15:34:16 -04:00 |
|
Anders Schack-Mulligen
|
80eb0a2df6
|
Apply suggestions from code review
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-04-19 15:45:58 +02:00 |
|
Anders Schack-Mulligen
|
7d84cfacef
|
Java: Add MapKeyContent and MapValueContent.
|
2021-04-19 14:06:27 +02:00 |
|
Anders Schack-Mulligen
|
39862740e0
|
Java: Convert support for fluent interfaces.
|
2021-04-19 14:06:27 +02:00 |
|
Anders Schack-Mulligen
|
60965b0d8c
|
Java: Adjust some csv models.
|
2021-04-19 14:02:19 +02:00 |
|
Anders Schack-Mulligen
|
a27dac029f
|
Java: Use shared flow summary library for csv models.
|
2021-04-19 14:02:19 +02:00 |
|
Mathias Vorreiter Pedersen
|
e36b42a03f
|
Java: Fix invalid id in experimental query
The invalid id broke CI here: https://github.com/github/codeql/pull/5703 (see https://github.slack.com/archives/CPSEA0G22/p1618602834224600)
|
2021-04-17 09:47:15 +02:00 |
|
Anders Schack-Mulligen
|
605f28f741
|
Merge pull request #5686 from smowton/haby0/JsonHijacking
Java: JSONP Injection w/cleanups
|
2021-04-16 11:09:17 +02:00 |
|
Chris Smowton
|
c37994089c
|
Revert changes to unrelated query
|
2021-04-15 16:24:29 +01:00 |
|
haby0
|
dedf765542
|
Update java/ql/src/experimental/Security/CWE/CWE-352/JsonpInjectionLib.qll
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-04-15 22:59:22 +08:00 |
|
haby0
|
0e183ab4a4
|
Finish comment
|
2021-04-15 19:49:06 +08:00 |
|
Chris Smowton
|
fa36ba901a
|
Merge pull request #5471 from artem-smotrakov/el-injection
Java: Query for detecting Jakarta Expression Language injections
|
2021-04-15 12:39:34 +01:00 |
|
haby0
|
d269a7e717
|
CWE-598 reduction
|
2021-04-15 19:33:15 +08:00 |
|
haby0
|
216f204438
|
delete FilterClass
|
2021-04-15 19:28:25 +08:00 |
|
haby0
|
583d0889e2
|
delete tomcat-embed-core stub, update the ServletGetMethod class
|
2021-04-15 17:40:51 +08:00 |
|
haby0
|
5d05e4d224
|
Update java/ql/src/experimental/Security/CWE/CWE-352/JsonpInjectionLib.qll
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-04-15 17:28:53 +08:00 |
|
Chris Smowton
|
bd3b3178ba
|
Fix documentation of Modifier.qll
|
2021-04-15 09:16:51 +01:00 |
|
haby0
|
b3bdf89fc2
|
rm VerificationMethodFlowConfig, use springframework-5.2.3 stub
|
2021-04-15 10:25:40 +08:00 |
|
Anders Schack-Mulligen
|
f43d427875
|
Merge pull request #5645 from Marcono1234/marcono1234/primary-ql-class
Java: Override getAPrimaryQlClass() for more classes
|
2021-04-14 14:51:29 +02:00 |
|
Chris Smowton
|
591ac38c31
|
Merge pull request #5591 from Marcono1234/marcono1234/member-nested-type
Java: Add MemberType
|
2021-04-14 12:29:54 +01:00 |
|
Anders Schack-Mulligen
|
3b6cd0f681
|
Merge pull request #5661 from smowton/smowton/cleanup/call-is-exprparent
Make Call a subclass of ExprParent.
|
2021-04-14 10:49:33 +02:00 |
|
Chris Smowton
|
2965a1f204
|
Use Thread$State as an inner-class example
Map<>$Entry currently has odd generic notation that may be about to change.
|
2021-04-14 08:43:05 +01:00 |
|
haby0
|
77208bcc91
|
Fix the error that there is no VerificationMethodToIfFlowConfig
|
2021-04-14 13:14:43 +08:00 |
|
haby0
|
e2ed0d02b0
|
Delete existsFilterVerificationMethod and existsServletVerificationMethod, add from get handler to filter
|
2021-04-14 12:34:52 +08:00 |
|
haby0
|
37dae67a0d
|
Fix RequestResponseFlowConfig.isSink error
|
2021-04-14 09:55:24 +08:00 |
|
Marcono1234
|
d853f0c400
|
Java: Add MemberType
|
2021-04-13 18:55:20 +02:00 |
|
haby0
|
00235ed3b3
|
Update java/ql/src/semmle/code/java/frameworks/Servlets.qll
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-04-13 23:58:52 +08:00 |
|
haby0
|
25b012db48
|
Update java/ql/src/experimental/Security/CWE/CWE-352/JsonpInjection.ql
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-04-13 23:58:28 +08:00 |
|
haby0
|
7be45e7c5e
|
Update java/ql/src/experimental/Security/CWE/CWE-352/JsonpInjection.ql
Co-authored-by: Chris Smowton <smowton@github.com>
|
2021-04-13 23:56:17 +08:00 |
|