p0wn4j
|
6841f5f7c4
|
Java: Add NashornScriptEngine detection in ScriptEngine query
Java: Add NashornScriptEngine detection in ScriptEngine query
Java: Add NashornScriptEngine detection in ScriptEngine query
Java: Add NashornScriptEngine detection in ScriptEngine query
|
2021-03-06 16:19:07 +04:00 |
|
Artem Smotrakov
|
0695b2a1fb
|
Removed TaintedSpringRequestBody
|
2021-03-04 20:27:39 +01:00 |
|
Artem Smotrakov
|
43a07bb13a
|
Better sink in SandboxedJexlFlowConfig
|
2021-02-20 11:17:51 +01:00 |
|
Artem Smotrakov
|
042c0b005e
|
Covered sandboxes for JEXL 2
- Updated SandboxedJexlFlowConfig to cover JEXL 2
- Added SandboxedJexl2 test
|
2021-02-11 22:57:26 +01:00 |
|
Artem Smotrakov
|
7543df60da
|
Callable.call() should not be a sink in JexlInjection.ql
|
2021-02-11 20:37:23 +01:00 |
|
Artem Smotrakov
|
af0f361ac8
|
Updated JexlInjection.ql to check for sandboxes
- Added a dataflow config to track setting a sandbox
on JexlBuilder
- Added SandboxedJexl3.java test
|
2021-02-10 22:19:45 +01:00 |
|
Artem Smotrakov
|
7d2d27394b
|
Java: Added a source and a taint step for JexlInjectionConfig
- Added TaintedSpringRequestBody source
- Added returningTaintedDataFromBean() taint step
- Added tests
|
2021-01-17 22:28:42 +01:00 |
|
Artem Smotrakov
|
99401f6e84
|
Java: Query for detecting JEXL injections
|
2021-01-17 14:19:26 +01:00 |
|
Rasmus Wriedt Larsen
|
7a54d0b493
|
Java: Move files in experiemntal dirs to be consistent
|
2020-09-02 13:19:21 +02:00 |
|