Tony Torralba
|
b876431950
|
Merge pull request #8706 from luchua-bc/java/unsafe-get-resource
Java: CWE-552 Add sources and sinks to to detect unsafe getResource calls in Java EE applications
|
2022-05-04 10:12:28 +02:00 |
|
Tony Torralba
|
02822c6284
|
Merge pull request #9013 from atorralba/atorralba/private-externalflow-imports
Java: Make more ExternalFlow imports private
|
2022-05-03 16:02:09 +02:00 |
|
Tony Torralba
|
c66e583aea
|
Make more ExternalFlow imports private
|
2022-05-03 10:31:29 +02:00 |
|
luchua-bc
|
920a7cd2e6
|
Put back the taint step removed during merge
|
2022-04-29 20:29:04 +00:00 |
|
luchua-bc
|
0aa1251ffe
|
Add more test cases
|
2022-04-29 02:31:43 +00:00 |
|
Chuan-kai Lin
|
d6f0bbb816
|
Fix syntax errors in QL comments
|
2022-04-28 11:53:36 -07:00 |
|
luchua-bc
|
590b9d8519
|
Standardize the query and update qldoc
|
2022-04-27 22:17:17 +00:00 |
|
Tony Torralba
|
e99cee4913
|
Merge branch 'main' into java/unsafe-get-resource
|
2022-04-27 16:45:42 +02:00 |
|
Tony Torralba
|
b69d81ce24
|
Make all imports of ExternalFlow private
|
2022-04-26 13:48:44 +02:00 |
|
luchua-bc
|
f0c4b1955b
|
Change getResource() to be a taint step
|
2022-04-19 15:55:09 +00:00 |
|
luchua-bc
|
7029802f3b
|
Add sinks for getClass() and getClassLoader()
|
2022-04-11 21:03:48 +00:00 |
|
luchua-bc
|
eccd97c7b7
|
Query to detect unsafe getResource calls in Java EE applications
|
2022-04-09 01:14:15 +00:00 |
|
Tom Hvitved
|
b91858e7cf
|
Java: Implement ContentSet
|
2022-04-04 13:51:44 +02:00 |
|
Anders Schack-Mulligen
|
f28da00ec4
|
Java: Fix qldoc as followup to https://github.com/github/codeql/pull/8323
|
2022-03-31 12:50:36 +02:00 |
|
Chris Smowton
|
9675f34cf5
|
Merge pull request #8257 from luchua-bc/java/insecure-webview-resource-response
Java: CWE-200 Query to detect insecure WebResourceResponse implementation
|
2022-03-30 15:56:27 +01:00 |
|
luchua-bc
|
fa2a6a7da3
|
Remove unnecessary taint step and update qldoc
|
2022-03-29 17:52:49 +00:00 |
|
Tony Torralba
|
e564481e9f
|
Organize imports
|
2022-03-29 11:38:24 +02:00 |
|
Tony Torralba
|
6799838ece
|
Simplification
|
2022-03-29 09:43:37 +02:00 |
|
luchua-bc
|
833d842113
|
Drop the getPath check from the library
|
2022-03-28 20:14:40 +00:00 |
|
luchua-bc
|
657f615703
|
Fine tune the query and update qldoc
|
2022-03-28 20:05:12 +00:00 |
|
Erik Krogh Kristensen
|
c7509c4dd3
|
Merge branch 'main' into deadCode
|
2022-03-15 09:19:14 +01:00 |
|
Joe Farebrother
|
d4b5eed3e4
|
Merge pull request #8410 from joefarebrother/sensitive-logging
Java: Promote Sensitive Logging query
|
2022-03-14 14:50:26 +00:00 |
|
Erik Krogh Kristensen
|
3bf5e06d53
|
delete all dead code
|
2022-03-14 13:03:31 +01:00 |
|
Erik Krogh Kristensen
|
cc43a94385
|
Java: remove duplicated class
|
2022-03-11 11:10:38 +01:00 |
|
Erik Krogh Kristensen
|
69353bb014
|
patch upper-case acronyms to be PascalCase
|
2022-03-11 11:10:33 +01:00 |
|
Joe Farebrother
|
4ad402f33f
|
Move from experimental to main
|
2022-03-03 12:13:14 +00:00 |
|
Ian Lynagh
|
1e62b485a5
|
Merge pull request #8241 from igfoo/igfoo/stats4
Java: Update stats and make some performance tweaks
|
2022-02-28 12:58:06 +00:00 |
|
luchua-bc
|
88d9694628
|
Query to detect insecure WebResourceResponse implementation
|
2022-02-26 02:03:35 +00:00 |
|
Chris Smowton
|
ff5d680837
|
Add missing substitution description
|
2022-02-25 19:12:25 +00:00 |
|
Ian Lynagh
|
0bf1370cd5
|
Java: Autoformat QL
|
2022-02-25 19:08:08 +00:00 |
|
Chris Smowton
|
ff303db034
|
Autoformat and fix qhelp
|
2022-02-25 17:33:08 +00:00 |
|
Chris Smowton
|
303927c9c9
|
Fix qhelp
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
35abc3f9a3
|
Update and rename ComparingValueOfSensetiveHeader.java to Test.java
|
2022-02-25 17:33:08 +00:00 |
|
Ahmed Farid
|
899b8d03b2
|
Update TimingAttackAgainstHeader.ql
|
2022-02-25 17:33:07 +00:00 |
|
Ahmed Farid
|
308f86f66f
|
Update TimingAttackAgainstHeader.ql
|
2022-02-25 17:33:07 +00:00 |
|
Ahmed Farid
|
2eee6b4f69
|
Update TimingAttackAgainstHeader.ql
|
2022-02-25 17:33:07 +00:00 |
|
Ahmed Farid
|
7859288040
|
Update TimingAttackAgainstHeader.ql
|
2022-02-25 17:33:07 +00:00 |
|
Ahmed Farid
|
d83444cb18
|
Update TimingAttackAgainstHeader.ql
|
2022-02-25 17:33:07 +00:00 |
|
Ahmed Farid
|
e79c0eaa71
|
Update TimingAttackAgainstHeader.ql
|
2022-02-25 17:33:07 +00:00 |
|
Ahmed Farid
|
36cf1010f8
|
Update TimingAttackAgainstHeader.ql
|
2022-02-25 17:33:07 +00:00 |
|
Ahmed Farid
|
8e6f76d47a
|
Update TimingAttackAgainstHeader.qhelp
|
2022-02-25 17:33:07 +00:00 |
|
Ahmed Farid
|
fa8af6bf70
|
Update TimingAttackAgainstHeader.ql
|
2022-02-25 17:33:07 +00:00 |
|
Ahmed Farid
|
f96e47db09
|
Update ComparingValueOfSensetiveHeader.java
|
2022-02-25 17:33:07 +00:00 |
|
Ahmed Farid
|
09e054ace6
|
Update ComparingValueOfSensetiveHeader.java
|
2022-02-25 17:33:07 +00:00 |
|
Ahmed Farid
|
f758ed0d85
|
Update ComparingValueOfSensetiveHeader.java
|
2022-02-25 17:33:07 +00:00 |
|
ahmed532009
|
4a9ee5826d
|
Update TimingAttackAgainstHeader.qhelp
|
2022-02-25 17:33:07 +00:00 |
|
ahmed532009
|
6da9bc593f
|
Rename csrfComparison.java to ComparingValueOfSensetiveHeader.java
|
2022-02-25 17:33:07 +00:00 |
|
ahmed532009
|
aa488e532f
|
Update csrfComparison.java
|
2022-02-25 17:33:07 +00:00 |
|
Chris Smowton
|
333130b2a4
|
Abbreviate isSink
|
2022-02-25 17:33:07 +00:00 |
|
Chris Smowton
|
80a2b388bf
|
Update TimingAttackAgainstHeader.qhelp
|
2022-02-25 17:33:07 +00:00 |
|