github / github/codeql

Ruby: support sprintf formatted string with modulo operator

Đang mở
#15,945 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
question Ruby
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

I noticed that dataflow in Ruby isn't propagated to [Kernel.sprintf](https://ruby-doc.org/3.2.2/String.html#method-i-25) formatted strings, e.g. the stored xss query should flag this code in an ERB template:

```rb
<%# BAD: Kernel.sprintf modulo operator syntax %>
<%= "Welcome %{user}".html_safe % { user: @user.handle } %>
```

The string literal is parsed as a a single `Ast::StringTextComponent`, where it should probably also contain a `Ast::StringInterpolationComponent`. I tried to work around this problem using an additional taint step:

```ql
predicate isAdditionalSprintfTaintStep(DataFlow::Node node1, DataFlow::Node node2) {
exists(ModuloExpr expr, HashLiteral hash, StringLiteral str |
hash.getParent*() = expr.getRightOperand() and
str.getParent*() = expr.getLeftOperand() and
hash.getAKeyValuePair().getValue() = node1.asExpr().getExpr() and
str = node2.asExpr().getExpr()
)
}
```

which works for the code snippet above, but doesn't work when the dataflow gets a bit more complex:

```rb
<% sink = "Welcome %{user}".html_safe %>
<%= sink % { user: @user.handle } %>
```

I tried the following, but it doesn't work:

```ql
predicate isAdditionalSprintfTaintStep(DataFlow::Node node1, DataFlow::Node node2) {
exists(ModuloExpr expr, HashLiteral hash, StringLiteral str |
DataFlow::localExprFlow(hash.getAControlFlowNode(), expr.getRightOperand().getAControlFlowNode()) and
DataFlow::localExprFlow(str.getAControlFlowNode(), expr.getLeftOperand().getAControlFlowNode()) and
hash.getAKeyValuePair().getValue() = node1.asExpr().getExpr() and
str = node2.asExpr().getExpr()
)
}
```

How do I catch the insecure code snippet above using local dataflow?

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.