github / github/codeql

Evil RegEx from user input vulnerability is not reported by codeQL

Abierto
#13,530 4 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

I created a simple C# console application based on this article:
**_[Attacking Evil Regex: Understanding Regular Expression Denial of Service Attacks (ReDoS)](https://sec.okta.com/articles/2020/04/attacking-evil-regex-understanding-regular-expression-denial-service)_**

Running the CodeQL CLI didn't write any issues in the created .csv file (0 rows).

Here is the complete code:

```c#
using System.Text.RegularExpressions;

namespace ReDoS
{
internal class Program
{
static void Main(string[] args)
{
Console.WriteLine("UserName: ");
var userName = Console.ReadLine();

Console.WriteLine("Password: ");
var password = Console.ReadLine();

Console.WriteLine(Authenticate(userName, password));
}

public static string Authenticate(string userName, string password)
{
var pattern = userName;
var numMatches = Regex.Matches(password, pattern ).Count;
return numMatches == 0
? "OK"
: "Password must not contain userName!";
}
}
}
```

Needless to say, entering input as the below one results in indefinitely long execution, so this is a serious attack:

![image](https://github.com/github/codeql/assets/10605892/008d8245-1c73-404f-9991-e7dde1a3a2b0)

My question is: Is this a known issue, or am I missing something?

Thanks in advance for your time and attention,

Dimitre

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.