github / github/codeql

False positive for IncompleteHostnameRegExp in Ruby

Đang mở
#13,749 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
false-positive Ruby
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

**Description of the false positive**

There's a problem with the current implementation of `IncompleteHostnameRegExp` for Ruby. Specifically, it seems that the rule with report false positives for any `X.match(Y)` method call where `Y` is a `String` and `X` is any object with a `match` method.

The rule incorrectly "thinks" that `Y` is a regex being used for matching, likely because in Ruby's `String` class has a `match` method which takes a `String` parameter for defining the regex:

https://ruby-doc.org/3.2.2/String.html#method-i-match

In other words, the rule doesn't check that `X` is a known type for which the `match` method accepts a string argument which is used as a regex, and instead matches on any type for `X`.

**Code samples or links to source code**

Please see https://github.com/github/codeql/pull/13748 which includes a failing test which demonstrates the problem.

**URL to the alert on GitHub code scanning (optional)**

Can't share it since it's in a private repository 😬

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Read the IncompleteHostnameRegExp implementation and the failing Ruby test referenced in pull request #13748. Reproduce the X.match(Y) case described in the issue, then verify that the rule no longer reports a false positive for unsupported receiver types while preserving the intended detection.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
ruby
Lĩnh vực
security
Loại issue
Lỗi
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
42/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.