Skip to content

Latest commit

 

History

History
27 lines (24 loc) · 6.1 KB

coverage.rst

File metadata and controls

27 lines (24 loc) · 6.1 KB

Java framework & library support

Framework / library Package Flow sources Taint & value steps Sinks (total) CWE‑022 Path injection CWE‑079 Cross-site scripting CWE‑089 SQL injection CWE‑090 LDAP injection CWE‑094 Code injection CWE‑918 Request Forgery
Android android.* 52 481 181 1 3 67      
Android extensions androidx.* 5 183 60            
Apache Commons Collections org.apache.commons.collections, org.apache.commons.collections4   1600              
Apache Commons IO org.apache.commons.io   570 124 105         15
Apache Commons Lang org.apache.commons.lang3   425 6            
Apache Commons Text org.apache.commons.text   272              
Apache HttpComponents org.apache.hc.core5.*, org.apache.http 5 183 122   3       119
Apache Log4j 2 org.apache.logging.log4j   8 359            
Google Guava com.google.common.*   730 43 9          
JBoss Logging org.jboss.logging     324            
JSON-java org.json   236              
Java Standard Library java.* 10 4621 259 99   9     26
Java extensions javax.*, jakarta.* 69 4159 90 10 4 2 1 1 4
Kotlin Standard Library kotlin*   1849 16 14         2
Spring org.springframework.* 38 486 143 26   28 14   35
Others actions.osgi, antlr, ch.ethz.ssh2, cn.hutool.core.codec, com.alibaba.druid.sql, com.alibaba.fastjson2, com.amazonaws.auth, com.auth0.jwt.algorithms, com.azure.identity, com.esotericsoftware.kryo.io, com.esotericsoftware.kryo5.io, com.fasterxml.jackson.core, com.fasterxml.jackson.databind, com.google.gson, com.hubspot.jinjava, com.jcraft.jsch, com.microsoft.sqlserver.jdbc, com.mitchellbosecke.pebble, com.mongodb, com.opensymphony.xwork2, com.rabbitmq.client, com.sshtools.j2ssh.authentication, com.sun.crypto.provider, com.sun.jndi.ldap, com.sun.net.httpserver, com.sun.net.ssl, com.sun.rowset, com.sun.security.auth.module, com.sun.security.ntlm, com.sun.security.sasl.digest, com.thoughtworks.xstream, com.trilead.ssh2, com.unboundid.ldap.sdk, com.zaxxer.hikari, flexjson, freemarker.cache, freemarker.template, groovy.lang, groovy.text, groovy.util, hudson, io.jsonwebtoken, io.netty.bootstrap, io.netty.buffer, io.netty.channel, io.netty.handler.codec, io.netty.handler.ssl, io.netty.handler.stream, io.netty.resolver, io.netty.util, io.undertow.server.handlers.resource, javafx.scene.web, jenkins, jodd.json, liquibase.database.jvm, liquibase.statement.core, net.lingala.zip4j, net.schmizz.sshj, net.sf.json, net.sf.saxon.s9api, ognl, okhttp3, org.acegisecurity, org.antlr.runtime, org.apache.commons.codec, org.apache.commons.compress.archivers.tar, org.apache.commons.exec, org.apache.commons.httpclient.util, org.apache.commons.jelly, org.apache.commons.jexl2, org.apache.commons.jexl3, org.apache.commons.lang, org.apache.commons.logging, org.apache.commons.net, org.apache.commons.ognl, org.apache.cxf.catalog, org.apache.cxf.common.classloader, org.apache.cxf.common.jaxb, org.apache.cxf.common.logging, org.apache.cxf.configuration.jsse, org.apache.cxf.helpers, org.apache.cxf.resource, org.apache.cxf.staxutils, org.apache.cxf.tools.corba.utils, org.apache.cxf.tools.util, org.apache.cxf.transform, org.apache.directory.ldap.client.api, org.apache.hadoop.fs, org.apache.hadoop.hive.metastore, org.apache.hadoop.hive.ql.exec, org.apache.hadoop.hive.ql.metadata, org.apache.hc.client5.http.async.methods, org.apache.hc.client5.http.classic.methods, org.apache.hc.client5.http.fluent, org.apache.hive.hcatalog.templeton, org.apache.ibatis.jdbc, org.apache.ibatis.mapping, org.apache.log4j, org.apache.shiro.authc, org.apache.shiro.codec, org.apache.shiro.jndi, org.apache.shiro.mgt, org.apache.sshd.client.session, org.apache.struts.beanvalidation.validation.interceptor, org.apache.struts2, org.apache.tools.ant, org.apache.tools.zip, org.apache.velocity.app, org.apache.velocity.runtime, org.codehaus.cargo.container.installer, org.codehaus.groovy.control, org.dom4j, org.eclipse.jetty.client, org.fusesource.leveldbjni, org.geogebra.web.full.main, org.gradle.api.file, org.hibernate, org.influxdb, org.jboss.vfs, org.jdbi.v3.core, org.jenkins.ui.icon, org.jenkins.ui.symbol, org.jooq, org.keycloak.models.map.storage, org.kohsuke.stapler, org.lastaflute.web, org.mvel2, org.openjdk.jmh.runner.options, org.owasp.esapi, org.pac4j.jwt.config.encryption, org.pac4j.jwt.config.signature, org.scijava.log, org.slf4j, org.thymeleaf, org.xml.sax, org.xmlpull.v1, org.yaml.snakeyaml, play.libs.ws, play.mvc, ratpack.core.form, ratpack.core.handling, ratpack.core.http, ratpack.exec, ratpack.form, ratpack.func, ratpack.handling, ratpack.http, ratpack.util, retrofit2, software.amazon.awssdk.transfer.s3.model, sun.jvmstat.perfdata.monitor.protocol.local, sun.jvmstat.perfdata.monitor.protocol.rmi, sun.misc, sun.net.ftp, sun.net.www.protocol.http, sun.security.acl, sun.security.jgss.krb5, sun.security.krb5, sun.security.pkcs, sun.security.pkcs11, sun.security.provider, sun.security.ssl, sun.security.x509, sun.tools.jconsole 133 10525 908 140 6 22 18   208
Totals   312 26328 2635 404 16 128 33 1 409