mirror of
https://github.com/github/codeql.git
synced 2025-12-18 09:43:15 +01:00
Given CharSequence is often used as an alias for String, ensure taint through toString is flowing
63 lines
4.5 KiB
Plaintext
63 lines
4.5 KiB
Plaintext
| A.java:10:19:10:25 | taint(...) | A.java:15:10:15:11 | b2 |
|
|
| A.java:20:19:20:25 | taint(...) | A.java:25:10:25:11 | b2 |
|
|
| A.java:33:23:33:29 | taint(...) | A.java:34:10:34:27 | toByteArray(...) |
|
|
| A.java:46:27:46:33 | taint(...) | A.java:47:10:47:30 | toByteArray(...) |
|
|
| A.java:55:58:55:64 | taint(...) | A.java:61:10:61:16 | dh.data |
|
|
| A.java:78:19:78:25 | taint(...) | A.java:81:10:81:21 | filterOutput |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:18:10:18:16 | aaaargs |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:21:10:21:10 | s |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:24:10:24:15 | concat |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:27:10:27:13 | pars |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:30:10:30:15 | method |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:33:10:33:16 | complex |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:36:10:36:20 | constructed |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:39:10:39:16 | valueOf |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:42:10:42:25 | valueOfSubstring |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:45:10:45:18 | badEscape |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:48:10:48:14 | token |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:51:10:51:21 | fluentConcat |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:68:10:68:13 | cond |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:71:10:71:14 | logic |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:73:10:73:39 | endsWith(...) |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:76:10:76:14 | logic |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:79:10:79:14 | logic |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:87:10:87:16 | trimmed |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:89:10:89:14 | split |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:91:10:91:14 | lower |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:93:10:93:14 | upper |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:95:10:95:14 | bytes |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:97:10:97:17 | toString |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:99:10:99:13 | subs |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:101:10:101:13 | repl |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:103:10:103:16 | replAll |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:105:10:105:18 | replFirst |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:108:10:108:14 | chars |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:110:10:110:19 | translated |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:123:12:123:25 | serializedData |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:135:12:135:27 | deserializedData |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:144:10:144:21 | taintedArray |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:146:10:146:22 | taintedArray2 |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:148:10:148:22 | taintedArray3 |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:151:10:151:44 | toURL(...) |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:154:10:154:37 | toPath(...) |
|
|
| B.java:15:21:15:27 | taint(...) | B.java:157:10:157:46 | toFile(...) |
|
|
| CharSeq.java:7:26:7:32 | taint(...) | CharSeq.java:8:12:8:14 | seq |
|
|
| CharSeq.java:7:26:7:32 | taint(...) | CharSeq.java:11:12:11:21 | seqFromSeq |
|
|
| CharSeq.java:7:26:7:32 | taint(...) | CharSeq.java:14:12:14:24 | stringFromSeq |
|
|
| MethodFlow.java:7:22:7:28 | taint(...) | MethodFlow.java:8:10:8:16 | tainted |
|
|
| MethodFlow.java:9:31:9:37 | taint(...) | MethodFlow.java:10:10:10:17 | tainted2 |
|
|
| MethodFlow.java:11:35:11:41 | taint(...) | MethodFlow.java:12:10:12:17 | tainted3 |
|
|
| MethodFlow.java:11:35:11:41 | taint(...) | MethodFlow.java:30:10:30:25 | ... + ... |
|
|
| MethodFlow.java:17:42:17:48 | taint(...) | MethodFlow.java:35:10:35:25 | ... + ... |
|
|
| StringBuilderTests.java:9:15:9:21 | taint(...) | StringBuilderTests.java:11:10:11:22 | toString(...) |
|
|
| StringBuilderTests.java:25:15:25:21 | taint(...) | StringBuilderTests.java:27:10:27:22 | toString(...) |
|
|
| StringBuilderTests.java:33:15:33:21 | taint(...) | StringBuilderTests.java:31:10:34:29 | toString(...) |
|
|
| StringBuilderTests.java:39:42:39:48 | taint(...) | StringBuilderTests.java:43:10:43:22 | toString(...) |
|
|
| StringBuilderTests.java:48:69:48:75 | taint(...) | StringBuilderTests.java:50:10:50:22 | toString(...) |
|
|
| StringBuilderTests.java:56:24:56:30 | taint(...) | StringBuilderTests.java:57:10:57:22 | toString(...) |
|
|
| StringBuilderTests.java:63:19:63:25 | taint(...) | StringBuilderTests.java:64:10:64:22 | toString(...) |
|
|
| Varargs.java:7:8:7:14 | taint(...) | Varargs.java:14:10:14:10 | s |
|
|
| Varargs.java:8:8:8:14 | taint(...) | Varargs.java:19:10:19:10 | s |
|
|
| Varargs.java:8:17:8:23 | taint(...) | Varargs.java:19:10:19:10 | s |
|
|
| Varargs.java:9:23:9:29 | taint(...) | Varargs.java:24:10:24:10 | s |
|