Skip to content
Merged
Show file tree
Hide file tree
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion cpp/ql/src/Security/CWE/CWE-014/MemsetMayBeDeleted.ql
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
* @security-severity 7.8
* @precision high
* @tags security
* external/cwe/cwe-14
* external/cwe/cwe-014
*/

import cpp
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
* to it.
* @id cpp/count-untrusted-data-external-api
* @kind table
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import cpp
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
* to it.
* @id cpp/count-untrusted-data-external-api-ir
* @kind table
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import cpp
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
* @precision low
* @problem.severity error
* @security-severity 7.8
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import cpp
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
* @precision low
* @problem.severity error
* @security-severity 7.8
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import cpp
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
* @tags correctness
* security
* experimental
* external/cwe/cwe-20
* external/cwe/cwe-020
*/

import cpp
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
* @precision medium
* @id cs/password-in-configuration
* @tags security
* external/cwe/cwe-13
* external/cwe/cwe-013
* external/cwe/cwe-256
* external/cwe/cwe-313
*/
Expand Down
2 changes: 1 addition & 1 deletion csharp/ql/src/Security Features/CWE-011/ASPNetDebug.ql
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
* @tags security
* maintainability
* frameworks/asp.net
* external/cwe/cwe-11
* external/cwe/cwe-011
* external/cwe/cwe-532
*/

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
* @id cs/web/large-max-request-length
* @tags security
* frameworks/asp.net
* external/cwe/cwe-16
* external/cwe/cwe-016
*/

import csharp
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
* @id cs/web/request-validation-disabled
* @tags security
* frameworks/asp.net
* external/cwe/cwe-16
* external/cwe/cwe-016
*/

import csharp
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
* to it.
* @id cs/count-untrusted-data-external-api
* @kind table
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import csharp
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
* @security-severity 7.8
* @precision medium
* @tags security
* external/cwe/cwe-20
* external/cwe/cwe-020
*/

import semmle.code.csharp.serialization.Serialization
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
* @precision low
* @problem.severity error
* @security-severity 7.8
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import csharp
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
* @precision high
* @id cs/web/missing-global-error-handler
* @tags security
* external/cwe/cwe-12
* external/cwe/cwe-012
* external/cwe/cwe-248
*/

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
* to it.
* @id go/count-untrusted-data-external-api
* @kind table
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import go
Expand Down
2 changes: 1 addition & 1 deletion go/ql/src/Security/CWE-020/IncompleteHostnameRegexp.ql
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
* @id go/incomplete-hostname-regexp
* @tags correctness
* security
* external/cwe/cwe-20
* external/cwe/cwe-020
*/

import go
Expand Down
2 changes: 1 addition & 1 deletion go/ql/src/Security/CWE-020/MissingRegexpAnchor.ql
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
* @id go/regex/missing-regexp-anchor
* @tags correctness
* security
* external/cwe/cwe-20
* external/cwe/cwe-020
*/

import go
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
* @id go/suspicious-character-in-regex
* @tags correctness
* security
* external/cwe/cwe-20
* external/cwe/cwe-020
*/

import go
Expand Down
2 changes: 1 addition & 1 deletion go/ql/src/Security/CWE-020/UntrustedDataToExternalAPI.ql
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
* @precision low
* @problem.severity error
* @security-severity 7.8
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import go
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
* @precision low
* @problem.severity error
* @security-severity 7.8
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import go
Expand Down
2 changes: 1 addition & 1 deletion go/ql/src/experimental/CWE-090/LDAPInjection.ql
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
* @id go/ldap-injection
* @tags security
* experimental
* external/cwe/cwe-90
* external/cwe/cwe-090
*/

import go
Expand Down
2 changes: 1 addition & 1 deletion go/ql/src/experimental/CWE-74/DsnInjection.ql
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
* @id go/dsn-injection
* @tags security
* experimental
* external/cwe/cwe-74
* external/cwe/cwe-074
*/

import go
Expand Down
2 changes: 1 addition & 1 deletion go/ql/src/experimental/CWE-74/DsnInjectionLocal.ql
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
* @id go/dsn-injection-local
* @tags security
* experimental
* external/cwe/cwe-74
* external/cwe/cwe-074
*/

import go
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
* @id go/html-template-escaping-passthrough
* @tags security
* experimental
* external/cwe/cwe-79
* external/cwe/cwe-079
*/

import go
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
* to it.
* @id java/count-untrusted-data-external-api
* @kind table
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import java
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
* @precision low
* @problem.severity error
* @security-severity 7.8
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import java
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
* @precision high
* @id java/netty-http-request-or-response-splitting
* @tags security
* external/cwe/cwe-93
* external/cwe/cwe-093
* external/cwe/cwe-113
*/

Expand Down
2 changes: 1 addition & 1 deletion javascript/ql/src/Electron/DisablingWebSecurity.ql
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
* @precision very-high
* @tags security
* frameworks/electron
* external/cwe/cwe-79
* external/cwe/cwe-079
* @id js/disabling-electron-websecurity
*/

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
* to it.
* @id js/count-untrusted-data-external-api
* @kind table
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import javascript
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
* @precision low
* @problem.severity error
* @security-severity 7.8
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import javascript
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
* @problem.severity error
* @security-severity 7.8
* @tags experimental
* security external/cwe/cwe-20
* security external/cwe/cwe-020
*/

import javascript
Expand Down
4 changes: 2 additions & 2 deletions python/ql/src/Expressions/UseofInput.ql
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,8 @@
* @kind problem
* @tags security
* correctness
* security/cwe/cwe-94
* security/cwe/cwe-95
* external/cwe/cwe-094
* external/cwe/cwe-095
* @problem.severity error
* @security-severity 9.8
* @sub-severity high
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
* to it.
* @id py/count-untrusted-data-external-api
* @kind table
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import python
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
* @precision low
* @problem.severity error
* @security-severity 7.8
* @tags security external/cwe/cwe-20
* @tags security external/cwe/cwe-020
*/

import python
Expand Down
2 changes: 1 addition & 1 deletion python/ql/src/Security/CWE-020/CookieInjection.ql
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
* @security-severity 5.0
* @id py/cookie-injection
* @tags security
* external/cwe/cwe-20
* external/cwe/cwe-020
*/

import python
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
* @id py/incomplete-url-substring-sanitization
* @tags correctness
* security
* external/cwe/cwe-20
* external/cwe/cwe-020
*/

import python
Expand Down
2 changes: 1 addition & 1 deletion python/ql/src/experimental/Security/CWE-094/Js2Py.ql
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
* @id py/js2py-rce
* @tags security
* experimental
* external/cwe/cwe-94
* external/cwe/cwe-094
*/

import python
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
* @precision high
* @id rb/server-side-template-injection
* @tags security
* external/cwe/cwe-94
* external/cwe/cwe-094
*/

import codeql.ruby.DataFlow
Expand Down
Loading