Rasmus Wriedt Larsen
|
3cdd875e9f
|
Python: Move experimental UnsafeUnpack to new dataflow API
|
2023-08-28 15:31:07 +02:00 |
|
Rasmus Wriedt Larsen
|
3edb9d1011
|
Python: Move experimental TokenBuiltFromUUID to new dataflow API
|
2023-08-28 15:31:07 +02:00 |
|
Rasmus Wriedt Larsen
|
acde1920e7
|
Python: Move UntrustedDataToExternalAPI to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
657b1997cc
|
Python: Move FullServerSideRequestForgery and PartialServerSideRequestForgery to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
dbfe517555
|
Python: Move HardcodedCredentials to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
46322b717a
|
Python: Move XmlBomb to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
add1077532
|
Python: Move RegexInjection to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
c6caf83dfe
|
Python: Move PolynomialReDoS to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
4c336990e5
|
Python: Move XpathInjection to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
60e45335dd
|
Python: Move Xxe to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
4c76ca6127
|
Python: Move UrlRedirect to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
6f08e73dbc
|
Python: Move UnsafeDeserialization to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
dd074173d2
|
Python: Move WeakSensitiveDataHashing to new dataflow API
I adopted helper predicates to do the "heavy" lifting of .asPathNode1(), maybe I like this approach better... let me know what you think 😊
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
9d6b96dfd2
|
Python: Move CleartextStorage to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
70095446b6
|
Python: Move CleartextLogging to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
cca78f31ff
|
Python: Move PamAuthorization to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
dcd96083e8
|
Python: Move StackTraceExposure to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
f75e65c67d
|
Python: Move LogInjection to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
88cf9c99b0
|
Python: Move CodeInjection to new dataflow API
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
05573904a5
|
Python: Move LdapInjection to new dataflow API
We could have switched to a stateful config, but I tried to keep changes
as straight forward as possible.
|
2023-08-28 15:27:50 +02:00 |
|
Rasmus Wriedt Larsen
|
c360346e9e
|
Python: Move ReflectedXss to new dataflow API
|
2023-08-28 15:27:49 +02:00 |
|
Rasmus Wriedt Larsen
|
b30142c1d7
|
Python: Move CommandInjection to new dataflow API
|
2023-08-28 15:27:49 +02:00 |
|
Rasmus Wriedt Larsen
|
700841e9b0
|
Python: Move UnsafeShellCommandConstruction to new dataflow API
|
2023-08-28 15:27:49 +02:00 |
|
Rasmus Wriedt Larsen
|
d4e4e2d426
|
Python: Move TarSlip to new dataflow API
|
2023-08-28 15:27:49 +02:00 |
|
Rasmus Wriedt Larsen
|
e97032909a
|
Python: Move PathInjection to new dataflow API
|
2023-08-28 15:27:49 +02:00 |
|
Rasmus Wriedt Larsen
|
245c24077d
|
Python: Move SqlInjection to new dataflow API
|
2023-08-28 15:27:49 +02:00 |
|
Michael Nebel
|
e19c7758ed
|
C#: Cleanup NugetPackages.cs.
|
2023-08-28 15:19:16 +02:00 |
|
Michael Nebel
|
6e4865ddd9
|
C#: Download nuget.exe to the source directory in case it is not installed.
|
2023-08-28 15:14:13 +02:00 |
|
Michael Nebel
|
b6c2ea520b
|
C#: Some re-factoring of NugetPackages and logic for file downloading.
|
2023-08-28 15:14:13 +02:00 |
|
yoff
|
2e981e330b
|
Merge pull request #14059 from RasmusWL/fix-loginjection-tests
Python: Fix stdlib sinks in LogInjection query
|
2023-08-28 14:44:51 +02:00 |
|
amammad
|
68392e7ae7
|
V1
|
2023-08-28 22:23:51 +10:00 |
|
yoff
|
6e05246daa
|
Merge pull request #13935 from yoff/python/mad-on-externals
Python: MaD on externals
|
2023-08-28 14:04:54 +02:00 |
|
Rasmus Wriedt Larsen
|
c807ab4216
|
Python: Apply suggestions from code review
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2023-08-28 14:04:22 +02:00 |
|
yoff
|
826b8e6aa5
|
Merge pull request #14067 from RasmusWL/modern-dataflowquerytests
Python: Adopt tests to new `DataflowQueryTest`
|
2023-08-28 13:54:34 +02:00 |
|
erik-krogh
|
78487d437f
|
add test for await using in TypeScript
|
2023-08-28 13:30:35 +02:00 |
|
erik-krogh
|
1e3387f2c5
|
Merge branch 'main' into ts52
|
2023-08-28 13:22:56 +02:00 |
|
Michael Nebel
|
e7dbe9f289
|
Merge pull request #14028 from michaelnebel/csharp/dependencygetfiles
C#: Improve GetFiles in the Dependency Manager.
|
2023-08-28 12:53:28 +02:00 |
|
Rasmus Wriedt Larsen
|
38b78128c0
|
Merge pull request #13990 from RasmusWL/experimental-cleanup
Python: Port old experimental points-to based queries
|
2023-08-28 12:11:17 +02:00 |
|
Rasmus Wriedt Larsen
|
889cb7a95b
|
Python: Adopt tests to new DataflowQueryTest
Co-authored-by: Rasmus Lerchedahl Petersen <yoff@github.com>
|
2023-08-28 11:44:01 +02:00 |
|
Rasmus Wriedt Larsen
|
9c44235782
|
Python: Modernize DataflowQueryTest.qll
Co-authored-by: Rasmus Lerchedahl Petersen <yoff@github.com>
|
2023-08-28 11:40:41 +02:00 |
|
Rasmus Wriedt Larsen
|
7cba6cd1d8
|
Python: Update .expected files
Due to change in path-graph, and including LHS of assignments
|
2023-08-28 11:33:44 +02:00 |
|
Rasmus Wriedt Larsen
|
0f242475f2
|
Merge branch 'main' into experimental-cleanup
|
2023-08-28 11:01:22 +02:00 |
|
Rasmus Wriedt Larsen
|
0dca8a5d86
|
Python: Remove old points-to modeling file
Since all of this was ported already
|
2023-08-28 10:40:45 +02:00 |
|
Rasmus Wriedt Larsen
|
39e2b133e9
|
Python: Fix naming
|
2023-08-28 10:40:33 +02:00 |
|
erik-krogh
|
be2712698b
|
add support for await using in the JS parser
|
2023-08-28 09:34:13 +02:00 |
|
erik-krogh
|
1cbee6a8a4
|
delete leftover todo comment that was implemented
|
2023-08-28 08:40:35 +02:00 |
|
amammad
|
25c60c455e
|
v1
|
2023-08-27 23:53:45 +10:00 |
|
Mathias Vorreiter Pedersen
|
bb1712b489
|
Merge branch 'main' into reuse-even-more-nodes
|
2023-08-26 18:08:58 +01:00 |
|
Alex Ford
|
9957e2683b
|
Merge pull request #13313 from maikypedia/maikypedia/ldap-improper-auth
Ruby: Add Improper LDAP Authentication query (CWE-287)
|
2023-08-25 20:52:34 +01:00 |
|
Maiky
|
17565cde75
|
Add JWT Security Queries
|
2023-08-25 21:28:53 +02:00 |
|