github / github/codeql

CodeQL miss to detect a vulnerability because of irrelvant code?

Abierto
#17,957 4 comentarios 0 reacciones 0 asignados Ver en GitHub
question
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

The problem is when I scan these files of code:
./main.js:
```javascript
(() => {})(), // this line makes the codeql neglect the vulnerability?
(() => {
let fe = require('./source.js').s;
let e = fe();
window.location.href = e;
})();
```
./source.js:
```javascript
module.exports.s = function() {
let e = window.location.href.split("#")[1];
return decodeURIComponent(e);
};
```
CodeQL doesn't report any vulnerability but if I comment the first line of main.js, like:
```javascript
// (() => {})(),
(() => {
let fe = require('./source.js').s;
let e = fe();
window.location.href = e;
})();
```
It detected one, which is:
```csv
"Client-side URL redirect","Client-side URL redirection based on unvalidated user input may cause redirection to malicious web sites.","error","Untrusted URL redirection depends on a [[""user-provided value""|""relative:///source.js:2:11:2:30""]].
Untrusted URL redirection depends on a [[""user-provided value""|""relative:///source.js:2:11:2:25""]].","/main.js","5","26","5","26"
```

Is there an issue? Since the part of code `(() => {})()` which seems irrelevant to the vulnerability to me affects the query result.

The version of the codeql that I use:
```bash
CodeQL command-line toolchain release 2.18.3.
Copyright (C) 2019-2024 GitHub, Inc.
Unpacked in: ...
Analysis results depend critically on separately distributed query and
extractor modules. To list modules that are visible to the toolchain,
use 'codeql resolve qlpacks' and 'codeql resolve languages'.
```

And here is the command I use:
```bash
codeql database create --language=javascript codeql-database --source-root="./sourcecode"
codeql database analyze ./codeql-database/ $CODE_QL/codeql-repo/javascript/ql/src/Security/CWE-601/ClientSideUrlRedirect.ql --format=csv --output="result.csv" --threads=10
cat result.csv | grep redirect
```

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Reproduce the scan with main.js and source.js using the provided database creation and ClientSideUrlRedirect.ql command, comparing results with and without the first IIFE. Inspect the reported locations and query output to determine why the unrelated statement changes the result; done means the behavior is explained and the relevant CodeQL analysis issue is addressed.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
javascript
Área
security, tooling
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Bastante claro
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.