github / github/codeql

explicit java Function<X,Y> implementation is not tainted?

未關閉
#15,494 3 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
Java question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

I hit on an issue while implementing a taint tracking use case. So I've prepared a minimal example that showcases the issue:
Here is the java code:
```java
import java.util.Optional;
import java.util.function.Function;

public class SourceToSinkBug {
public class DoubleToString implements Function {
public String apply(Double x) { return x.toString(); }
}
public String flow0() { // toString() is tainted
Double source0 = 1.0;
String sink0 = source0.toString();
return sink0;
}

public String flow1() { // Lambda is tainted
Double source1 = 1.0;
Optional opt1 = Optional.of(source1);
Optional map1 = opt1.map(x -> x.toString());
String sink1 = map1.get();
return sink1;
}
public String flow2() { // BUG?: DoubleToString *isn't* tainted?
Double source2 = 2.0;
Optional opt2 = Optional.of(source2);
Optional map2 = opt2.map(new DoubleToString());
String sink2 = map2.get();
return sink2;
}
public String flow3() { // Inline function is tainted
Double source3 = 3.0;
Optional opt3 = Optional.of(source3);
Optional map3 = opt3.map(
new Function(){ public String apply(Double x) { return x.toString(); }});
String sink3 = map3.get();
return sink3;
}
}
```
I expect all flows to be in the query result when we taint source(x) with sink(x). However flow2 is not reported?

Here is the codeql query:
```codeql
import semmle.code.java.dataflow.DataFlow
import semmle.code.java.dataflow.TaintTracking

class Source1 extends VarAccess {
Source1() { this.getVariable().getName().matches("source%")}
}
class Sink1 extends VarAccess {
Sink1() { this.getVariable().getName().matches("sink%") }
}

// source% to sink%
module Config implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) { source.asExpr() instanceof Source1 }
predicate isSink(DataFlow::Node sink) { sink.asExpr() instanceof Sink1 }
}

module MyFlow = TaintTracking::Global;

from DataFlow::Node source, DataFlow::Node sink
where MyFlow::flow(source, sink)
select source, sink, "source to sink"
```

貢獻指南

開啟貢獻指南

研究方向

Start with the supplied DataFlow and TaintTracking imports and the Java example, comparing how the lambda, inline Function, and DoubleToString implementation are modeled. Run the provided query against the example and investigate why flow2 is absent; done means the query reports flow2 along with flow0, flow1, and flow3.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
java
領域
security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。