Skip to content

Addition of Synacktivs CodeQL analysis #28

@AlLongley

Description

@AlLongley

Synacktiv have done an awesome write up of using CodeQL for source/sink analysis for detection of Java deserialization that would go well in this list

Writeup:
https://www.synacktiv.com/en/publications/finding-gadgets-like-its-2022

Associated tool/codebase:
https://github.com/synacktiv/QLinspector

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions