github / github/codeql

Can't find dataflow for js in Vue module

Abierto
#11,043 0 comentarios 0 reacciones 0 asignados Ver en GitHub
question
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Can't find dataflow for js in Vue module**
```


Vue xss test


网站列表



{{ site.name }}


{{reflect }}



new Vue({
el: '#app',
data() {
return {
info: null
}
},
mounted() {
axios
.get('http://127.0.0.1/test.json')
.then(response => (this.info = response.data.sites))
.catch(function(error) { // 请求失败处理
console.log(error);
});
}
})

```
There will be a xss Vulnerability if the test.json return an dangerous payload and data flows to v-html。
I try to find the dataflow to discover this kind of Vulnerability,but find the dataflow in Vue is none。

The rule is like this:
```
import javascript
import DataFlow::PathGraph

class XSSTracker extends TaintTracking::Configuration {
XSSTracker() {
// unique identifier for this configuration
this = "XSSTracker"
}

override predicate isSource(DataFlow::Node source) {
exists( MethodCallExpr m,Parameter p,VarRef v|
m.getCalleeName()="then"
and p.getParent() = m.getAnArgument()
and p.toString()=v.toString()|
source.asExpr() =v.getParent().getParent() )
}

override predicate isSink(DataFlow::Node sink) {
exists(Vue::VHtmlAttribute v, Label l,DotExpr p |
l.getParent() = p and
v.getFile() = p.getFile() and
v.getAttr().getValue().indexOf(l.toString())>=0
|l.getParent() = sink.asExpr()
)
}
}


from XSSTracker pt, DataFlow::PathNode source, DataFlow::PathNode sink
where pt.hasFlowPath(source, sink)
select sink.getNode(), source, sink, "find a xss dataflow"
```

The sink is **this.info** and the source is **response.data.sites** can be found
,but the dataflow from source to sink in code **this.info = response.data.sites** can't be found。

How can I solve this problem by codeql?
and i want to know if javascript code in Vue can be connect by TaintTracking analysis?

Thanks~

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.