Y
Hacker News
new
|
ask
|
show
|
jobs
Using QL to find a remote code execution vulnerability in Apache Struts
(
lgtm.com
)
1 points
by
mossity
3205 days ago
1 comments
mossity
3205 days ago
Reading about CVE-2017-9805 it was really interesting to learn that the company that discovered it was using a Datalog-like language in order to query Java code for vulnerability patterns.
https://en.wikipedia.org/wiki/Semmle
link
https://en.wikipedia.org/wiki/Semmle