Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 49218cd

Browse files
committed
Credential-username models
1 parent 18661ee commit 49218cd

19 files changed

Lines changed: 79 additions & 0 deletions

java/ql/lib/ext/com.sun.istack.internal.tools.model.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,3 +4,4 @@ extensions:
44
extensible: sinkModel
55
data:
66
- ["com.sun.istack.internal.tools", "DefaultAuthenticator$AuthInfo", False, "AuthInfo", "(URL, String, String)", "credential-password", "Argument[2]", "manual"]
7+
- ["com.sun.istack.internal.tools", "DefaultAuthenticator$AuthInfo", False, "AuthInfo", "(URL, String, String)", "credential-username", "Argument[1]", "manual"]
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["com.sun.jndi.ldap", "DigestClientId", False, "DigestClientId", "(int, String, int, String, Control[], OutputStream, String, String, Object, Hashtable)", "credential-username", "Argument[7]", "manual"]
7+
- ["com.sun.jndi.ldap", "LdapClient", False, "getInstance", "(boolean, String, int, String, int, int, OutputStream, int, String, Control[], String, String, Object, Hashtable)", "credential-username", "Argument[11]", "manual"]
8+
- ["com.sun.jndi.ldap", "LdapPoolManager", False, "getLdapClient", "(String, int, String, int, int, OutputStream, int, String, Control[], String, String, Object, Hashtable)", "credential-username", "Argument[10]", "manual"]
9+
- ["com.sun.jndi.ldap", "SimpleClientId", False, "SimpleClientId", "(int, String, int, String, Control[], OutputStream, String, String, Object)", "credential-username", "Argument[7]", "manual"]

java/ql/lib/ext/com.sun.net.httpserver.model.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,3 +4,5 @@ extensions:
44
extensible: sinkModel
55
data:
66
- ["com.sun.net.httpserver", "BasicAuthenticator", False, "checkCredentials", "(String, String)", "credential-password", "Argument[1]", "manual"]
7+
- ["com.sun.net.httpserver", "BasicAuthenticator", False, "checkCredentials", "(String, String)", "credential-username", "Argument[0]", "manual"]
8+
- ["com.sun.net.httpserver", "HttpPrincipal", False, "HttpPrincipal", "(String, String)", "credential-username", "Argument[0]", "manual"]

java/ql/lib/ext/com.sun.rowset.model.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,3 +5,4 @@ extensions:
55
data:
66
- ["com.sun.rowset", "JdbcRowSetImpl", False, "JdbcRowSetImpl", "(String, String, String)", "credential-password", "Argument[2]", "manual"]
77
- ["com.sun.rowset", "JdbcRowSetImpl", False, "setPassword", "(String)", "credential-password", "Argument[0]", "manual"]
8+
- ["com.sun.rowset", "JdbcRowSetImpl", False, "JdbcRowSetImpl", "(String, String, String)", "credential-username", "Argument[1]", "manual"]

java/ql/lib/ext/com.sun.security.ntlm.model.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,3 +6,5 @@ extensions:
66
- ["com.sun.security.ntlm", "Client", False, "Client", "(String, String, String, String, char[])", "credential-password", "Argument[4]", "manual"]
77
- ["com.sun.security.ntlm", "NTLM", False, "getP1", "(char[])", "credential-password", "Argument[0]", "manual"]
88
- ["com.sun.security.ntlm", "NTLM", False, "getP2", "(char[])", "credential-password", "Argument[0]", "manual"]
9+
- ["com.sun.security.ntlm", "Client", False, "Client", "(String, String, String, String, char[])", "credential-username", "Argument[2]", "manual"]
10+
- ["com.sun.security.ntlm", "Server", False, "getPassword", "(String, String)", "credential-username", "Argument[1]", "manual"]

java/ql/lib/ext/com.sun.security.sasl.digest.model.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,3 +5,4 @@ extensions:
55
data:
66
- ["com.sun.security.sasl.digest", "DigestMD5Base", False, "generateResponseValue", "(String, String, String, String, String, char[], byte[], byte[], int, byte[])", "credential-password", "Argument[5]", "manual"]
77
- ["com.sun.security.sasl.digest", "DigestMD5Server", False, "generateResponseAuth", "(String, char[], byte[], int, byte[])", "credential-password", "Argument[1]", "manual"]
8+
- ["com.sun.security.sasl.digest", "DigestMD5Server", False, "generateResponseAuth", "(String, char[], byte[], int, byte[])", "credential-username", "Argument[0]", "manual"]

java/ql/lib/ext/com.sun.tools.internal.ws.wscompile.model.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,3 +4,4 @@ extensions:
44
extensible: sinkModel
55
data:
66
- ["com.sun.tools.internal.ws.wscompile", "AuthInfo", False, "AuthInfo", "(URL, String, String)", "credential-password", "Argument[2]", "manual"]
7+
- ["com.sun.tools.internal.ws.wscompile", "AuthInfo", False, "AuthInfo", "(URL, String, String)", "credential-username", "Argument[1]", "manual"]

java/ql/lib/ext/java.net.model.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,7 @@ extensions:
2626
- ["java.net", "URLClassLoader", False, "URLClassLoader", "(URL[],ClassLoader,URLStreamHandlerFactory)", "", "Argument[0]", "request-forgery", "manual"]
2727
- ["java.net", "URLClassLoader", False, "URLClassLoader", "(URL[],ClassLoader)", "", "Argument[0]", "request-forgery", "manual"]
2828
- ["java.net", "URLClassLoader", False, "URLClassLoader", "(URL[])", "", "Argument[0]", "request-forgery", "manual"]
29+
- ["java.net", "PasswordAuthentication", False, "PasswordAuthentication", "(String, char[])", "credential-username", "Argument[0]", "manual"]
2930
- addsTo:
3031
pack: codeql/java-all
3132
extensible: summaryModel

java/ql/lib/ext/java.sql.model.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@ extensions:
1717
- ["java.sql", "Statement", True, "executeLargeUpdate", "", "", "Argument[0]", "sql-injection", "manual"]
1818
- ["java.sql", "Statement", True, "executeQuery", "", "", "Argument[0]", "sql-injection", "manual"]
1919
- ["java.sql", "Statement", True, "executeUpdate", "", "", "Argument[0]", "sql-injection", "manual"]
20+
- ["java.sql", "DriverManager", False, "getConnection", "(String, String, String)", "credential-username", "Argument[1]", "manual"]
2021
- addsTo:
2122
pack: codeql/java-all
2223
extensible: summaryModel
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/java-all
4+
extensible: sinkModel
5+
data:
6+
- ["javax.print.attribute.standard", "JobOriginatingUserName", False, "JobOriginatingUserName", "(String, Locale)", "credential-username", "Argument[0]", "manual"]
7+
- ["javax.print.attribute.standard", "RequestingUserName", False, "RequestingUserName", "(String, Locale)", "credential-username", "Argument[0]", "manual"]

0 commit comments

Comments
 (0)