Skip to content

Commit 9809d30

Browse files
author
Naman Jain
committed
file renaming and updated expected file
1 parent adc8bf3 commit 9809d30

File tree

2 files changed

+24
-0
lines changed

2 files changed

+24
-0
lines changed

javascript/ql/test/query-tests/Security/CWE-754/UnvalidatedDynamicMethodCall.expected

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,12 @@ nodes
1010
| UnsafeDynamicMethodAccess.js:15:5:15:21 | obj[message.name] |
1111
| UnsafeDynamicMethodAccess.js:15:9:15:15 | message |
1212
| UnsafeDynamicMethodAccess.js:15:9:15:20 | message.name |
13+
| UnvalidatedDynamicMethodCall2.js:13:9:13:47 | action |
14+
| UnvalidatedDynamicMethodCall2.js:13:18:13:47 | actions ... action) |
15+
| UnvalidatedDynamicMethodCall2.js:13:30:13:46 | req.params.action |
16+
| UnvalidatedDynamicMethodCall2.js:13:30:13:46 | req.params.action |
17+
| UnvalidatedDynamicMethodCall2.js:14:13:14:18 | action |
18+
| UnvalidatedDynamicMethodCall2.js:14:13:14:18 | action |
1319
| UnvalidatedDynamicMethodCall.js:14:7:14:41 | action |
1420
| UnvalidatedDynamicMethodCall.js:14:7:14:41 | action |
1521
| UnvalidatedDynamicMethodCall.js:14:16:14:41 | actions ... action] |
@@ -19,6 +25,12 @@ nodes
1925
| UnvalidatedDynamicMethodCall.js:15:11:15:16 | action |
2026
| UnvalidatedDynamicMethodCall.js:15:11:15:16 | action |
2127
| UnvalidatedDynamicMethodCall.js:15:11:15:16 | action |
28+
| UnvalidatedDynamicMethodCallGood4.js:14:13:14:51 | action |
29+
| UnvalidatedDynamicMethodCallGood4.js:14:22:14:51 | actions ... action) |
30+
| UnvalidatedDynamicMethodCallGood4.js:14:34:14:50 | req.params.action |
31+
| UnvalidatedDynamicMethodCallGood4.js:14:34:14:50 | req.params.action |
32+
| UnvalidatedDynamicMethodCallGood4.js:16:17:16:22 | action |
33+
| UnvalidatedDynamicMethodCallGood4.js:16:17:16:22 | action |
2234
| tst.js:6:39:6:40 | ev |
2335
| tst.js:6:39:6:40 | ev |
2436
| tst.js:7:9:7:39 | name |
@@ -91,6 +103,11 @@ edges
91103
| UnsafeDynamicMethodAccess.js:15:9:15:20 | message.name | UnsafeDynamicMethodAccess.js:15:5:15:21 | obj[message.name] |
92104
| UnsafeDynamicMethodAccess.js:15:9:15:20 | message.name | UnsafeDynamicMethodAccess.js:15:5:15:21 | obj[message.name] |
93105
| UnsafeDynamicMethodAccess.js:15:9:15:20 | message.name | UnsafeDynamicMethodAccess.js:15:5:15:21 | obj[message.name] |
106+
| UnvalidatedDynamicMethodCall2.js:13:9:13:47 | action | UnvalidatedDynamicMethodCall2.js:14:13:14:18 | action |
107+
| UnvalidatedDynamicMethodCall2.js:13:9:13:47 | action | UnvalidatedDynamicMethodCall2.js:14:13:14:18 | action |
108+
| UnvalidatedDynamicMethodCall2.js:13:18:13:47 | actions ... action) | UnvalidatedDynamicMethodCall2.js:13:9:13:47 | action |
109+
| UnvalidatedDynamicMethodCall2.js:13:30:13:46 | req.params.action | UnvalidatedDynamicMethodCall2.js:13:18:13:47 | actions ... action) |
110+
| UnvalidatedDynamicMethodCall2.js:13:30:13:46 | req.params.action | UnvalidatedDynamicMethodCall2.js:13:18:13:47 | actions ... action) |
94111
| UnvalidatedDynamicMethodCall.js:14:7:14:41 | action | UnvalidatedDynamicMethodCall.js:15:11:15:16 | action |
95112
| UnvalidatedDynamicMethodCall.js:14:7:14:41 | action | UnvalidatedDynamicMethodCall.js:15:11:15:16 | action |
96113
| UnvalidatedDynamicMethodCall.js:14:7:14:41 | action | UnvalidatedDynamicMethodCall.js:15:11:15:16 | action |
@@ -101,6 +118,11 @@ edges
101118
| UnvalidatedDynamicMethodCall.js:14:24:14:40 | req.params.action | UnvalidatedDynamicMethodCall.js:14:16:14:41 | actions ... action] |
102119
| UnvalidatedDynamicMethodCall.js:14:24:14:40 | req.params.action | UnvalidatedDynamicMethodCall.js:14:16:14:41 | actions ... action] |
103120
| UnvalidatedDynamicMethodCall.js:14:24:14:40 | req.params.action | UnvalidatedDynamicMethodCall.js:14:16:14:41 | actions ... action] |
121+
| UnvalidatedDynamicMethodCallGood4.js:14:13:14:51 | action | UnvalidatedDynamicMethodCallGood4.js:16:17:16:22 | action |
122+
| UnvalidatedDynamicMethodCallGood4.js:14:13:14:51 | action | UnvalidatedDynamicMethodCallGood4.js:16:17:16:22 | action |
123+
| UnvalidatedDynamicMethodCallGood4.js:14:22:14:51 | actions ... action) | UnvalidatedDynamicMethodCallGood4.js:14:13:14:51 | action |
124+
| UnvalidatedDynamicMethodCallGood4.js:14:34:14:50 | req.params.action | UnvalidatedDynamicMethodCallGood4.js:14:22:14:51 | actions ... action) |
125+
| UnvalidatedDynamicMethodCallGood4.js:14:34:14:50 | req.params.action | UnvalidatedDynamicMethodCallGood4.js:14:22:14:51 | actions ... action) |
104126
| tst.js:6:39:6:40 | ev | tst.js:7:27:7:28 | ev |
105127
| tst.js:6:39:6:40 | ev | tst.js:7:27:7:28 | ev |
106128
| tst.js:6:39:6:40 | ev | tst.js:9:9:9:10 | ev |
@@ -164,7 +186,9 @@ edges
164186
| tst.js:49:19:49:22 | name | tst.js:49:14:49:23 | obj2[name] |
165187
#select
166188
| UnsafeDynamicMethodAccess.js:15:5:15:21 | obj[message.name] | UnsafeDynamicMethodAccess.js:5:37:5:38 | ev | UnsafeDynamicMethodAccess.js:15:5:15:21 | obj[message.name] | Invocation of method with $@ name may dispatch to unexpected target and cause an exception. | UnsafeDynamicMethodAccess.js:5:37:5:38 | ev | user-controlled |
189+
| UnvalidatedDynamicMethodCall2.js:14:13:14:18 | action | UnvalidatedDynamicMethodCall2.js:13:30:13:46 | req.params.action | UnvalidatedDynamicMethodCall2.js:14:13:14:18 | action | Invocation of method with $@ name may dispatch to unexpected target and cause an exception. | UnvalidatedDynamicMethodCall2.js:13:30:13:46 | req.params.action | user-controlled |
167190
| UnvalidatedDynamicMethodCall.js:15:11:15:16 | action | UnvalidatedDynamicMethodCall.js:14:24:14:40 | req.params.action | UnvalidatedDynamicMethodCall.js:15:11:15:16 | action | Invocation of method with $@ name may dispatch to unexpected target and cause an exception. | UnvalidatedDynamicMethodCall.js:14:24:14:40 | req.params.action | user-controlled |
191+
| UnvalidatedDynamicMethodCallGood4.js:16:17:16:22 | action | UnvalidatedDynamicMethodCallGood4.js:14:34:14:50 | req.params.action | UnvalidatedDynamicMethodCallGood4.js:16:17:16:22 | action | Invocation of method with $@ name may dispatch to unexpected target and cause an exception. | UnvalidatedDynamicMethodCallGood4.js:14:34:14:50 | req.params.action | user-controlled |
168192
| tst.js:9:5:9:16 | obj[ev.data] | tst.js:6:39:6:40 | ev | tst.js:9:5:9:16 | obj[ev.data] | Invocation of method with $@ name may dispatch to unexpected target and cause an exception. | tst.js:6:39:6:40 | ev | user-controlled |
169193
| tst.js:11:5:11:13 | obj[name] | tst.js:6:39:6:40 | ev | tst.js:11:5:11:13 | obj[name] | Invocation of method with $@ name may dispatch to unexpected target and cause an exception. | tst.js:6:39:6:40 | ev | user-controlled |
170194
| tst.js:18:5:18:6 | fn | tst.js:6:39:6:40 | ev | tst.js:18:5:18:6 | fn | Invocation of method with $@ name may dispatch to unexpected target and cause an exception. | tst.js:6:39:6:40 | ev | user-controlled |

0 commit comments

Comments
 (0)