github / github/codeql

Information exposure alert on intentional input validation exception

オープン
#16,867 コメント 3 件 リアクション 0 件 担当者 0 名 GitHub で見る
false-positive Java
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

### Discussed in https://github.com/github/codeql/discussions/16845

Originally posted by **slominskir** June 26, 2024
Is it possible to throw an exception on user input validation failure, and use the Exception.getMessage() to pass this onto the user, while allowing CodeQL scan to pass? I'm referring to a Java project. It appears a level of indirection is required such that Exception.getMessage() cannot be used. This appears to be a false positive though. I have a generic "InvalidInputException" that my validation method throws when it finds a user supplied parameter that is invalid. I'm not revealing any stack trace at all, just using the Exception.getMessage() method to carry a message to the user.

CodeQL is saying:

```
Information exposure through a stack trace
```

Using Exception.getMessage() to carry a message actually intended for the user isn't even a stack trace. At a minimum this should be filed under something like "Information exposure through an Exception". Seems like user input validation cannot easily use an Exception to perform notification of validation failure. Bug or feature?

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

リンクされているCodeQLのディスカッションと、issueで説明されているJavaの検証例外のシナリオから始めてください。リポジトリのファイル、クエリ、テスト、エントリポイントは指定されていません。情報漏えいアラートを調査し、それが誤検知であるか、または必要な動作を確定した時点で作業は完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
java
領域
security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。