github / github/codeql

Evil RegEx from user input vulnerability is not reported by codeQL

Đang mở
#13,530 4 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

I created a simple C# console application based on this article:
**_[Attacking Evil Regex: Understanding Regular Expression Denial of Service Attacks (ReDoS)](https://sec.okta.com/articles/2020/04/attacking-evil-regex-understanding-regular-expression-denial-service)_**

Running the CodeQL CLI didn't write any issues in the created .csv file (0 rows).

Here is the complete code:

```c#
using System.Text.RegularExpressions;

namespace ReDoS
{
internal class Program
{
static void Main(string[] args)
{
Console.WriteLine("UserName: ");
var userName = Console.ReadLine();

Console.WriteLine("Password: ");
var password = Console.ReadLine();

Console.WriteLine(Authenticate(userName, password));
}

public static string Authenticate(string userName, string password)
{
var pattern = userName;
var numMatches = Regex.Matches(password, pattern ).Count;
return numMatches == 0
? "OK"
: "Password must not contain userName!";
}
}
}
```

Needless to say, entering input as the below one results in indefinitely long execution, so this is a serious attack:

![image](https://github.com/github/codeql/assets/10605892/008d8245-1c73-404f-9991-e7dde1a3a2b0)

My question is: Is this a known issue, or am I missing something?

Thanks in advance for your time and attention,

Dimitre

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.