Evil RegEx from user input vulnerability is not reported by codeQL
- Lingua principale
- CodeQL
- Stelle
- 10.1k
- Fork
- 2.1k
- Merge medio
- 2g 15h
- PR unite (30g)
- 141
Descrizione
I created a simple C# console application based on this article:
**_[Attacking Evil Regex: Understanding Regular Expression Denial of Service Attacks (ReDoS)](https://sec.okta.com/articles/2020/04/attacking-evil-regex-understanding-regular-expression-denial-service)_**
Running the CodeQL CLI didn't write any issues in the created .csv file (0 rows).
Here is the complete code:
```c#
using System.Text.RegularExpressions;
namespace ReDoS
{
internal class Program
{
static void Main(string[] args)
{
Console.WriteLine("UserName: ");
var userName = Console.ReadLine();
Console.WriteLine("Password: ");
var password = Console.ReadLine();
Console.WriteLine(Authenticate(userName, password));
}
public static string Authenticate(string userName, string password)
{
var pattern = userName;
var numMatches = Regex.Matches(password, pattern ).Count;
return numMatches == 0
? "OK"
: "Password must not contain userName!";
}
}
}
```
Needless to say, entering input as the below one results in indefinitely long execution, so this is a serious attack:

My question is: Is this a known issue, or am I missing something?
Thanks in advance for your time and attention,
Dimitre
Guida per i contributori
Apri la guida per i contributori
Valutazione
Questa issue non è ancora stata valutata.