FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
codeql-queries/java/github/SensitiveInformation.qll at main · advanced-security/codeql-queries · GitHub
This repository was archived by the owner on Apr 4, 2025. It is now read-only.
advanced-security
codeql-queries
Repository navigation
Code
Pull requests
Discussions
Actions
Security and quality
Insights
Expand file tree
Breadcrumbs
codeql-queries
/
java
/
github
/
SensitiveInformation.qll
Copy path
More file actions
More file actions
Latest commit
History
History
History
44 lines (40 loc) · 1.33 KB
Breadcrumbs
codeql-queries
/
java
/
github
/
SensitiveInformation.qll
Copy path
File metadata and controls
44 lines (40 loc) · 1.33 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
import
java
import
semmle.code.java.dataflow.DataFlow
import
semmle.code.java.dataflow.FlowSources
import
semmle.code.java.dataflow.TaintTracking2
abstract
class
SensitiveInformationSources
extends
DataFlow
::
Node
{
}
class
HttpSession
extends
SensitiveInformationSources
{
HttpSession
(
)
{
exists
(
MethodAccess
ma
|
// https://docs.oracle.com/javaee/5/api/javax/servlet/http/HttpSession.html
// Assumption: Nothing from the Session object should be logged
ma
.
getMethod
(
)
.
getDeclaringType
(
)
.
hasQualifiedName
(
"javax.servlet.http"
,
"HttpSession"
)
and
this
.
asExpr
(
)
=
ma
)
}
}
class
Properties
extends
SensitiveInformationSources
{
Properties
(
)
{
exists
(
MethodAccess
ma
|
ma
.
getMethod
(
)
.
hasName
(
"getProperty"
)
and
this
.
asExpr
(
)
=
ma
)
}
}
class
SensitiveVariables
extends
SensitiveInformationSources
{
SensitiveVariables
(
)
{
exists
(
Variable
v
|
(
// User data
v
.
getName
(
)
.
toLowerCase
(
)
.
regexpMatch
(
".*(username|passport|fingerprint|dob|ssi).*"
)
or
// Creds / Secrets / Tokens
v
.
getName
(
)
.
toLowerCase
(
)
.
regexpMatch
(
".*(password|pwd|hash|secret|token|session).*"
)
or
// Card Numbers
v
.
getName
(
)
.
toLowerCase
(
)
.
regexpMatch
(
".*(cardnumber|cvv|sortcode|accountnumber).*"
)
)
and
this
.
asExpr
(
)
=
v
.
getAnAccess
(
)
)
}
}
Back
|
FazBrowse Home
|
New Git URL