CodeQL miss to detect a vulnerability because of irrelvant code?
- Vorherrschende Sprache
- CodeQL
- Sterne
- 10.1k
- Forks
- 2.1k
- Ø Merge
- 2 T. 15 Std.
- Gemergte PRs (30 T.)
- 141
Beschreibung
The problem is when I scan these files of code:
./main.js:
```javascript
(() => {})(), // this line makes the codeql neglect the vulnerability?
(() => {
let fe = require('./source.js').s;
let e = fe();
window.location.href = e;
})();
```
./source.js:
```javascript
module.exports.s = function() {
let e = window.location.href.split("#")[1];
return decodeURIComponent(e);
};
```
CodeQL doesn't report any vulnerability but if I comment the first line of main.js, like:
```javascript
// (() => {})(),
(() => {
let fe = require('./source.js').s;
let e = fe();
window.location.href = e;
})();
```
It detected one, which is:
```csv
"Client-side URL redirect","Client-side URL redirection based on unvalidated user input may cause redirection to malicious web sites.","error","Untrusted URL redirection depends on a [[""user-provided value""|""relative:///source.js:2:11:2:30""]].
Untrusted URL redirection depends on a [[""user-provided value""|""relative:///source.js:2:11:2:25""]].","/main.js","5","26","5","26"
```
Is there an issue? Since the part of code `(() => {})()` which seems irrelevant to the vulnerability to me affects the query result.
The version of the codeql that I use:
```bash
CodeQL command-line toolchain release 2.18.3.
Copyright (C) 2019-2024 GitHub, Inc.
Unpacked in: ...
Analysis results depend critically on separately distributed query and
extractor modules. To list modules that are visible to the toolchain,
use 'codeql resolve qlpacks' and 'codeql resolve languages'.
```
And here is the command I use:
```bash
codeql database create --language=javascript codeql-database --source-root="./sourcecode"
codeql database analyze ./codeql-database/ $CODE_QL/codeql-repo/javascript/ql/src/Security/CWE-601/ClientSideUrlRedirect.ql --format=csv --output="result.csv" --threads=10
cat result.csv | grep redirect
```
Beitragsleitfaden
Rechercherichtung
Reproduziere den Scan mit main.js und source.js unter Verwendung des bereitgestellten Befehls zur Datenbankerstellung und ClientSideUrlRedirect.ql und vergleiche die Ergebnisse mit und ohne die erste IIFE. Untersuche die gemeldeten Positionen und die Abfrageausgabe, um festzustellen, warum die nicht zusammenhängende Anweisung das Ergebnis ändert; als erledigt gilt die Aufgabe, wenn das Verhalten erklärt und das relevante CodeQL-Analyseproblem behoben ist.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- javascript
- Bereich
- security, tooling
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 35/100