Evil RegEx from user input vulnerability is not reported by codeQL
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 141
Mô tả
I created a simple C# console application based on this article:
**_[Attacking Evil Regex: Understanding Regular Expression Denial of Service Attacks (ReDoS)](https://sec.okta.com/articles/2020/04/attacking-evil-regex-understanding-regular-expression-denial-service)_**
Running the CodeQL CLI didn't write any issues in the created .csv file (0 rows).
Here is the complete code:
```c#
using System.Text.RegularExpressions;
namespace ReDoS
{
internal class Program
{
static void Main(string[] args)
{
Console.WriteLine("UserName: ");
var userName = Console.ReadLine();
Console.WriteLine("Password: ");
var password = Console.ReadLine();
Console.WriteLine(Authenticate(userName, password));
}
public static string Authenticate(string userName, string password)
{
var pattern = userName;
var numMatches = Regex.Matches(password, pattern ).Count;
return numMatches == 0
? "OK"
: "Password must not contain userName!";
}
}
}
```
Needless to say, entering input as the below one results in indefinitely long execution, so this is a serious attack:

My question is: Is this a known issue, or am I missing something?
Thanks in advance for your time and attention,
Dimitre
Hướng dẫn đóng góp
Đánh giá
Issue này chưa được đánh giá.