github / github/codeql

Incorrect path generated C#

Abierto
#10,054 2 comentarios 0 reacciones 0 asignados Ver en GitHub
C# question
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

Hi,

Ran into this weird result with cs/path-injection, where we have this path:

![MicrosoftTeams-image (8)](https://user-images.githubusercontent.com/102255874/184916177-01d2f8a0-bc36-43af-bd95-26298dc7182d.png)

There's this step between this snippet of code in ExceptionExtension.cs:
```
StringBuilder sb = new StringBuilder();
while (null != exception)
{
sb.AppendLine(exception.ToString());
sb.AppendLine(exception.StackTrace);

// Try to loop every inner exception to see if there should be custom message
string customError = exception.GetCustomMessage();
if (!String.IsNullOrEmpty(customError))
{
sb.AppendLine(customError);
}
exception = exception.InnerException;
if (exception != null)
{
sb.AppendLine();
}
}
return sb.ToString(); //HERE
```
and this function in the EcpTraceFormatter.cs:

```
public override string ToString() //HERE
{
return EcpTraceHelper.GetTraceString(this.innerObject);
}
```

Codeql is following the ToString() method of EcpTraceFormatter instead of the ToString method of the StringBuilder. StringBuilder is of [StringBuilder Class (System.Text) | Microsoft Docs](https://docs.microsoft.com/en-us/dotnet/api/system.text.stringbuilder?view=net-6.0) class which isn't an extension of or related to EcpTraceFormatter so not sure why the codeql cli is confusing the two when constructing the path

Also wondering if this kind of issue has ever come up before - I replicated the scenario (two classes with a function with the same name) and the query worked as expected, plus haven't had issues with data paths from other queries. Not sure what might have caused the weird behavior in this case.

I'm also using the 2.8.4 cli, if this has been fixed in a later version.

Thanks,

Chanel

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.