X Tutup
Skip to content

Latest commit

 

History

History
12 lines (8 loc) · 607 Bytes

File metadata and controls

12 lines (8 loc) · 607 Bytes

0.1.2

Query Metadata Changes

  • Query java/predictable-seed now has a tag for CWE-337.

Minor Analysis Improvements

  • Query java/insecure-cookie now tolerates setting a cookie's secure flag to request.isSecure(). This means servlets that intentionally accept unencrypted connections will no longer raise an alert.
  • The query java/non-https-urls has been simplified and no longer requires its sinks to be MethodAccesses.
  • The logic to detect WebViews with JavaScript (and optionally file access) enabled in the query java/android/unsafe-android-webview-fetch has been improved.
X Tutup