CodeQL library for Ruby
codeql/ruby-all 0.8.15-dev (changelog, source)
Search

Module ServerSideRequestForgeryQuery

Provides a taint-tracking configuration for detecting “Server side request forgery” vulnerabilities.

Note, for performance reasons: only import this file if ServerSideRequestForgeryFlow is needed, otherwise ServerSideRequestForgeryCustomizations should be imported instead.

Import path

import codeql.ruby.security.ServerSideRequestForgeryQuery

Imports

BarrierGuards

Provides commonly used barriers to dataflow.

DataFlow

Provides classes for performing local (intra-procedural) and global (inter-procedural) data flow analyses.

ServerSideRequestForgery

Provides default sources, sinks and sanitizers for reasoning about server side request forgery, as well as extension points for adding your own.

TaintTracking

Classes

Configuration

A taint-tracking configuration for detecting “Server side request forgery” vulnerabilities. DEPRECATED: Use ServerSideRequestForgeryFlow

Aliases

ServerSideRequestForgeryFlow

Taint-tracking for detecting “Server side request forgery” vulnerabilities.