github / github/codeql

Incorrect path generated C#

Open
#10,054 2 comments 0 reactions 0 assignees View on GitHub
C# question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

Hi,

Ran into this weird result with cs/path-injection, where we have this path:

![MicrosoftTeams-image (8)](https://user-images.githubusercontent.com/102255874/184916177-01d2f8a0-bc36-43af-bd95-26298dc7182d.png)

There's this step between this snippet of code in ExceptionExtension.cs:
```
StringBuilder sb = new StringBuilder();
while (null != exception)
{
sb.AppendLine(exception.ToString());
sb.AppendLine(exception.StackTrace);

// Try to loop every inner exception to see if there should be custom message
string customError = exception.GetCustomMessage();
if (!String.IsNullOrEmpty(customError))
{
sb.AppendLine(customError);
}
exception = exception.InnerException;
if (exception != null)
{
sb.AppendLine();
}
}
return sb.ToString(); //HERE
```
and this function in the EcpTraceFormatter.cs:

```
public override string ToString() //HERE
{
return EcpTraceHelper.GetTraceString(this.innerObject);
}
```

Codeql is following the ToString() method of EcpTraceFormatter instead of the ToString method of the StringBuilder. StringBuilder is of [StringBuilder Class (System.Text) | Microsoft Docs](https://docs.microsoft.com/en-us/dotnet/api/system.text.stringbuilder?view=net-6.0) class which isn't an extension of or related to EcpTraceFormatter so not sure why the codeql cli is confusing the two when constructing the path

Also wondering if this kind of issue has ever come up before - I replicated the scenario (two classes with a function with the same name) and the query worked as expected, plus haven't had issues with data paths from other queries. Not sure what might have caused the weird behavior in this case.

I'm also using the 2.8.4 cli, if this has been fixed in a later version.

Thanks,

Chanel

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.