Java: Promote Groovy Code Injection from experimental#6062
Conversation
1fe9366 to
66a8f57
Compare
|
Force-pushed after rebasing |
|
|
|
@github/docs-content-codeql please review the |
|
|
There was a problem hiding this comment.
@atorralba - this LGTM ✨
A few minor comments for your consideration:
- minor nit on the change notes
- for the qhelp file, I've suggested a couple of minor updates but for some reason, I had to commit them onto your branch and could add them as suggestion (probably because the file hasn't been updated in your PR, sorry about that).
Hope this helps!
|
|
Co-authored-by: mc <42146119+mchammer01@users.noreply.github.com>
@mchammer01 I committed your suggestion, thanks for the review! |
mchammer01
left a comment
There was a problem hiding this comment.
Re-approving this PR from a docs perspective
| @@ -0,0 +1,84 @@ | |||
| edges | |||
There was a problem hiding this comment.
Is this an accidental commit? It looks unrelated to this PR.
There was a problem hiding this comment.
Yes, it's a mistake from a merge in which this should have been removed. Thanks for spotting this! Fixed in 3656580
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
RequestForgery.expected in experimental was an artifact from a merge that wasn't adequately removed
|
|
PR to promote the Groovy Code Injection query created in #5467
Changes
GroovyInjectionLib.qllfile was renamed and refactored to use the CSV sink model. Also, added some additional sinks and taint steps.Evaluation
CVE-2019-1003000 and CVE-2019-1003005 are correctly detected by this query (after adding some ad-hoc modeling for the Stapler framework)
To Consider
Added a flow summary for the
new url(/sitelet?url=https%3A%2F%2Fweb.archive.org%2Fweb%2F20260602224954%2Fhttps%3A%2F%2Fgithub.com%2Fgithub%2Fcodeql%2Fpull%2Ftainted)constructor that will probably affect other things apart from this query. Open to move that to a different PR if necessary.