github / github/codeql

Evil RegEx from user input vulnerability is not reported by codeQL

Aberta
#13,530 4 comentários 0 reações 0 responsáveis Ver no GitHub
Linguagem predominante
CodeQL
Estrelas
10.1k
Forks
2.1k
Merge médio
2d 15h
PRs com merge (30d)
141

Descrição

I created a simple C# console application based on this article:
**_[Attacking Evil Regex: Understanding Regular Expression Denial of Service Attacks (ReDoS)](https://sec.okta.com/articles/2020/04/attacking-evil-regex-understanding-regular-expression-denial-service)_**

Running the CodeQL CLI didn't write any issues in the created .csv file (0 rows).

Here is the complete code:

```c#
using System.Text.RegularExpressions;

namespace ReDoS
{
internal class Program
{
static void Main(string[] args)
{
Console.WriteLine("UserName: ");
var userName = Console.ReadLine();

Console.WriteLine("Password: ");
var password = Console.ReadLine();

Console.WriteLine(Authenticate(userName, password));
}

public static string Authenticate(string userName, string password)
{
var pattern = userName;
var numMatches = Regex.Matches(password, pattern ).Count;
return numMatches == 0
? "OK"
: "Password must not contain userName!";
}
}
}
```

Needless to say, entering input as the below one results in indefinitely long execution, so this is a serious attack:

![image](https://github.com/github/codeql/assets/10605892/008d8245-1c73-404f-9991-e7dde1a3a2b0)

My question is: Is this a known issue, or am I missing something?

Thanks in advance for your time and attention,

Dimitre

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Start with the complete C# console application in the issue and reproduce the empty result from the CodeQL CLI. Trace the C# regular-expression security query and its handling of user-controlled patterns; done means the provided example is reported as a ReDoS vulnerability.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
csharp
Domínio
security
Tipo de issue
Bug
Dificuldade
4/5
Tempo estimado
3-5 dias
Status de atividade
Estagnada
Clareza
Razoavelmente clara
Facilidade para iniciantes
25/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.