|
1 | 1 | #select
|
2 |
| -| tst.js:13:50:13:55 | origin | tst.js:12:28:12:34 | req.url | tst.js:13:50:13:55 | origin | $@ leak vulnerability due to a $@. | tst.js:14:5:14:59 | res.set ... , true) | Credential | tst.js:12:28:12:34 | req.url | misconfigured CORS header value | |
3 |
| -| tst.js:18:50:18:53 | null | tst.js:18:50:18:53 | null | tst.js:18:50:18:53 | null | $@ leak vulnerability due to a $@. | tst.js:19:5:19:59 | res.set ... , true) | Credential | tst.js:18:50:18:53 | null | misconfigured CORS header value | |
4 |
| -| tst.js:23:50:23:55 | "null" | tst.js:23:50:23:55 | "null" | tst.js:23:50:23:55 | "null" | $@ leak vulnerability due to a $@. | tst.js:24:5:24:59 | res.set ... , true) | Credential | tst.js:23:50:23:55 | "null" | misconfigured CORS header value | |
| 2 | +| apollo-test.js:11:25:11:28 | true | apollo-test.js:11:25:11:28 | true | apollo-test.js:11:25:11:28 | true | CORS misconfiguration due to a $@. | apollo-test.js:11:25:11:28 | true | permissive or user controlled value | |
| 3 | +| apollo-test.js:21:25:21:28 | null | apollo-test.js:21:25:21:28 | null | apollo-test.js:21:25:21:28 | null | CORS misconfiguration due to a $@. | apollo-test.js:21:25:21:28 | null | permissive or user controlled value | |
| 4 | +| apollo-test.js:26:25:26:35 | user_origin | apollo-test.js:8:33:8:39 | req.url | apollo-test.js:26:25:26:35 | user_origin | CORS misconfiguration due to a $@. | apollo-test.js:8:33:8:39 | req.url | permissive or user controlled value | |
| 5 | +| apollo-test.js:26:25:26:35 | user_origin | apollo-test.js:8:42:8:45 | true | apollo-test.js:26:25:26:35 | user_origin | CORS misconfiguration due to a $@. | apollo-test.js:8:42:8:45 | true | permissive or user controlled value | |
| 6 | +| express-test.js:26:17:26:19 | '*' | express-test.js:26:17:26:19 | '*' | express-test.js:26:17:26:19 | '*' | CORS misconfiguration due to a $@. | express-test.js:26:17:26:19 | '*' | permissive or user controlled value | |
| 7 | +| express-test.js:33:17:33:27 | user_origin | express-test.js:10:33:10:39 | req.url | express-test.js:33:17:33:27 | user_origin | CORS misconfiguration due to a $@. | express-test.js:10:33:10:39 | req.url | permissive or user controlled value | |
| 8 | +| express-test.js:33:17:33:27 | user_origin | express-test.js:10:42:10:45 | true | express-test.js:33:17:33:27 | user_origin | CORS misconfiguration due to a $@. | express-test.js:10:42:10:45 | true | permissive or user controlled value | |
| 9 | +| tst.js:13:50:13:55 | origin | tst.js:12:28:12:34 | req.url | tst.js:13:50:13:55 | origin | CORS misconfiguration due to a $@. | tst.js:12:28:12:34 | req.url | permissive or user controlled value | |
| 10 | +| tst.js:13:50:13:55 | origin | tst.js:12:37:12:40 | true | tst.js:13:50:13:55 | origin | CORS misconfiguration due to a $@. | tst.js:12:37:12:40 | true | permissive or user controlled value | |
| 11 | +| tst.js:18:50:18:53 | null | tst.js:18:50:18:53 | null | tst.js:18:50:18:53 | null | CORS misconfiguration due to a $@. | tst.js:18:50:18:53 | null | permissive or user controlled value | |
| 12 | +| tst.js:23:50:23:55 | "null" | tst.js:23:50:23:55 | "null" | tst.js:23:50:23:55 | "null" | CORS misconfiguration due to a $@. | tst.js:23:50:23:55 | "null" | permissive or user controlled value | |
5 | 13 | edges
|
| 14 | +| apollo-test.js:8:9:8:59 | user_origin | apollo-test.js:26:25:26:35 | user_origin | provenance | | |
| 15 | +| apollo-test.js:8:23:8:46 | url.par ... , true) | apollo-test.js:8:9:8:59 | user_origin | provenance | | |
| 16 | +| apollo-test.js:8:33:8:39 | req.url | apollo-test.js:8:23:8:46 | url.par ... , true) | provenance | | |
| 17 | +| apollo-test.js:8:42:8:45 | true | apollo-test.js:8:23:8:46 | url.par ... , true) | provenance | | |
| 18 | +| express-test.js:10:9:10:59 | user_origin | express-test.js:33:17:33:27 | user_origin | provenance | | |
| 19 | +| express-test.js:10:23:10:46 | url.par ... , true) | express-test.js:10:9:10:59 | user_origin | provenance | | |
| 20 | +| express-test.js:10:33:10:39 | req.url | express-test.js:10:23:10:46 | url.par ... , true) | provenance | | |
| 21 | +| express-test.js:10:42:10:45 | true | express-test.js:10:23:10:46 | url.par ... , true) | provenance | | |
6 | 22 | | tst.js:12:9:12:54 | origin | tst.js:13:50:13:55 | origin | provenance | |
|
7 | 23 | | tst.js:12:18:12:41 | url.par ... , true) | tst.js:12:9:12:54 | origin | provenance | |
|
8 | 24 | | tst.js:12:28:12:34 | req.url | tst.js:12:18:12:41 | url.par ... , true) | provenance | |
|
| 25 | +| tst.js:12:37:12:40 | true | tst.js:12:18:12:41 | url.par ... , true) | provenance | | |
9 | 26 | nodes
|
| 27 | +| apollo-test.js:8:9:8:59 | user_origin | semmle.label | user_origin | |
| 28 | +| apollo-test.js:8:23:8:46 | url.par ... , true) | semmle.label | url.par ... , true) | |
| 29 | +| apollo-test.js:8:33:8:39 | req.url | semmle.label | req.url | |
| 30 | +| apollo-test.js:8:42:8:45 | true | semmle.label | true | |
| 31 | +| apollo-test.js:11:25:11:28 | true | semmle.label | true | |
| 32 | +| apollo-test.js:21:25:21:28 | null | semmle.label | null | |
| 33 | +| apollo-test.js:26:25:26:35 | user_origin | semmle.label | user_origin | |
| 34 | +| express-test.js:10:9:10:59 | user_origin | semmle.label | user_origin | |
| 35 | +| express-test.js:10:23:10:46 | url.par ... , true) | semmle.label | url.par ... , true) | |
| 36 | +| express-test.js:10:33:10:39 | req.url | semmle.label | req.url | |
| 37 | +| express-test.js:10:42:10:45 | true | semmle.label | true | |
| 38 | +| express-test.js:26:17:26:19 | '*' | semmle.label | '*' | |
| 39 | +| express-test.js:33:17:33:27 | user_origin | semmle.label | user_origin | |
10 | 40 | | tst.js:12:9:12:54 | origin | semmle.label | origin |
|
11 | 41 | | tst.js:12:18:12:41 | url.par ... , true) | semmle.label | url.par ... , true) |
|
12 | 42 | | tst.js:12:28:12:34 | req.url | semmle.label | req.url |
|
| 43 | +| tst.js:12:37:12:40 | true | semmle.label | true | |
13 | 44 | | tst.js:13:50:13:55 | origin | semmle.label | origin |
|
14 | 45 | | tst.js:18:50:18:53 | null | semmle.label | null |
|
15 | 46 | | tst.js:23:50:23:55 | "null" | semmle.label | "null" |
|
|
0 commit comments