github / github/codeql

Question: Extending Query (UnsafeDeserialization.ql) for CWE-502

Đang mở
#14,004 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
Python question
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

Hi,

I am analysing python code in terms of vulnerability CWE-502 and am running query [UnsafeDeserialization.ql](https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-502/UnsafeDeserialization.ql) for this purpose. Now I would like to adapt the query to extend to more sources of untrusted data, namely:

1. I would like to mark local files as untrusted, marking the following example as vulnerable:
```
import yaml

def unsafe_load(filename):
with open(filename) as untrusted:
return yaml.load(untrusted)
```

2. I would like to mark function parameters as untrusted, marking the following example as vulnerable:
```
import yaml

def unsafe_load(untrusted):
return yaml.load(untrusted)
```

I am new to codeQL and after studying the documentation on how to write codeQL queries in Python and the codeQL repository, I am still not sure how and where I could extend the configuration to add these two sources. Based on [analyzing-data-flow-in-python](https://codeql.github.com/docs/codeql-language-guides/analyzing-data-flow-in-python/) it seems that I can use `Concepts::FileSystemAccess` and `DataFlow::ParameterNode` to model the sources and that I need to append them to the `isSource` predicate in the configuration. However, I am not sure what the current sources are based on `semmle.python.security.dataflow.UnsafeDeserializationQuery` in [UnsafeDeserializationQuery.qll](https://github.com/github/codeql/blob/main/python/ql/lib/semmle/python/security/dataflow/UnsafeDeserializationQuery.qll) and if there is any additional modification step that I need to take to run the new query.
Any help or clarifications would be greatly appreciated!

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Start with python/ql/src/Security/CWE-502/UnsafeDeserialization.ql and the referenced python/ql/lib/semmle/python/security/dataflow/UnsafeDeserializationQuery.qll. Read the analyzing-data-flow-in-python guidance, then trace the existing source configuration and relevant data-flow classes. Done means the query recognizes the local-file and function-parameter examples as unsafe deserialization sources and can be run successfully.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
python
Lĩnh vực
devtools, security
Loại issue
Tính năng
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
25/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.