github / github/codeql

Incorrect path generated C#

未关闭
#10,054 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
C# question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

Hi,

Ran into this weird result with cs/path-injection, where we have this path:

![MicrosoftTeams-image (8)](https://user-images.githubusercontent.com/102255874/184916177-01d2f8a0-bc36-43af-bd95-26298dc7182d.png)

There's this step between this snippet of code in ExceptionExtension.cs:
```
StringBuilder sb = new StringBuilder();
while (null != exception)
{
sb.AppendLine(exception.ToString());
sb.AppendLine(exception.StackTrace);

// Try to loop every inner exception to see if there should be custom message
string customError = exception.GetCustomMessage();
if (!String.IsNullOrEmpty(customError))
{
sb.AppendLine(customError);
}
exception = exception.InnerException;
if (exception != null)
{
sb.AppendLine();
}
}
return sb.ToString(); //HERE
```
and this function in the EcpTraceFormatter.cs:

```
public override string ToString() //HERE
{
return EcpTraceHelper.GetTraceString(this.innerObject);
}
```

Codeql is following the ToString() method of EcpTraceFormatter instead of the ToString method of the StringBuilder. StringBuilder is of [StringBuilder Class (System.Text) | Microsoft Docs](https://docs.microsoft.com/en-us/dotnet/api/system.text.stringbuilder?view=net-6.0) class which isn't an extension of or related to EcpTraceFormatter so not sure why the codeql cli is confusing the two when constructing the path

Also wondering if this kind of issue has ever come up before - I replicated the scenario (two classes with a function with the same name) and the query worked as expected, plus haven't had issues with data paths from other queries. Not sure what might have caused the weird behavior in this case.

I'm also using the 2.8.4 cli, if this has been fixed in a later version.

Thanks,

Chanel

贡献指南

打开贡献指南

调研方向

Start by tracing the path from the return in ExceptionExtension.cs through EcpTraceFormatter.cs and its ToString() method, focusing on why the StringBuilder result is associated with EcpTraceFormatter. Reproduce the report with two classes that define same-named methods and compare the generated path with CodeQL CLI 2.8.4; done means the path resolves the called method correctly.

由索引模型根据 Issue 内容生成。

评估

技术栈
csharp
领域
devtools, security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
需要澄清
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。