False positive for IncompleteHostnameRegExp in Ruby
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 141
Mô tả
**Description of the false positive**
There's a problem with the current implementation of `IncompleteHostnameRegExp` for Ruby. Specifically, it seems that the rule with report false positives for any `X.match(Y)` method call where `Y` is a `String` and `X` is any object with a `match` method.
The rule incorrectly "thinks" that `Y` is a regex being used for matching, likely because in Ruby's `String` class has a `match` method which takes a `String` parameter for defining the regex:
https://ruby-doc.org/3.2.2/String.html#method-i-match
In other words, the rule doesn't check that `X` is a known type for which the `match` method accepts a string argument which is used as a regex, and instead matches on any type for `X`.
**Code samples or links to source code**
Please see https://github.com/github/codeql/pull/13748 which includes a failing test which demonstrates the problem.
**URL to the alert on GitHub code scanning (optional)**
Can't share it since it's in a private repository 😬
Hướng dẫn đóng góp
Hướng nghiên cứu
Read the IncompleteHostnameRegExp implementation and the failing Ruby test referenced in pull request #13748. Reproduce the X.match(Y) case described in the issue, then verify that the rule no longer reports a false positive for unsupported receiver types while preserving the intended detection.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- ruby
- Lĩnh vực
- security
- Loại issue
- Lỗi
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 42/100