github / github/codeql

Can't find dataflow for js in Vue module

未关闭
#11,043 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

**Can't find dataflow for js in Vue module**
```


Vue xss test


网站列表



{{ site.name }}


{{reflect }}



new Vue({
el: '#app',
data() {
return {
info: null
}
},
mounted() {
axios
.get('http://127.0.0.1/test.json')
.then(response => (this.info = response.data.sites))
.catch(function(error) { // 请求失败处理
console.log(error);
});
}
})

```
There will be a xss Vulnerability if the test.json return an dangerous payload and data flows to v-html。
I try to find the dataflow to discover this kind of Vulnerability,but find the dataflow in Vue is none。

The rule is like this:
```
import javascript
import DataFlow::PathGraph

class XSSTracker extends TaintTracking::Configuration {
XSSTracker() {
// unique identifier for this configuration
this = "XSSTracker"
}

override predicate isSource(DataFlow::Node source) {
exists( MethodCallExpr m,Parameter p,VarRef v|
m.getCalleeName()="then"
and p.getParent() = m.getAnArgument()
and p.toString()=v.toString()|
source.asExpr() =v.getParent().getParent() )
}

override predicate isSink(DataFlow::Node sink) {
exists(Vue::VHtmlAttribute v, Label l,DotExpr p |
l.getParent() = p and
v.getFile() = p.getFile() and
v.getAttr().getValue().indexOf(l.toString())>=0
|l.getParent() = sink.asExpr()
)
}
}


from XSSTracker pt, DataFlow::PathNode source, DataFlow::PathNode sink
where pt.hasFlowPath(source, sink)
select sink.getNode(), source, sink, "find a xss dataflow"
```

The sink is **this.info** and the source is **response.data.sites** can be found
,but the dataflow from source to sink in code **this.info = response.data.sites** can't be found。

How can I solve this problem by codeql?
and i want to know if javascript code in Vue can be connect by TaintTracking analysis?

Thanks~

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。