github / github/codeql

False positive: Ruby: Kernel Open when File existence guard is present

Abierto
#16,943 3 comentarios 0 reacciones 0 asignados Ver en GitHub
false-positive
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Description of the false positive**

When `IO.read` is guarded by a check like `File.exists?`, isn't that a valid guard against injecting the `|` character into `Kernel.open`? I don't imagine that many systems out there have files lying around named `|.txt`.

**Code samples or links to source code**

https://github.com/github/codeql/blob/81593ece5aa7701ec0b103932f84ff65ae506e0b/ruby/ql/lib/codeql/ruby/security/KernelOpenQuery.qll#L83C1-L87

**URL to the alert on GitHub code scanning (optional)**
- https://github.com/Chainguard-Wolfi-Bites-Back/opensearch-project__logstash-output-opensearch/security/code-scanning/2
- https://github.com/opensearch-project/logstash-output-opensearch/blob/4221dffef4c1d9fd5ded5ae726ef2874fdd9ba5b/lib/logstash/outputs/opensearch/template_manager.rb#L55-L59

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.