github / github/codeql

CodeQL miss to detect a vulnerability because of irrelvant code?

オープン
#17,957 コメント 4 件 リアクション 0 件 担当者 0 名 GitHub で見る
question
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

The problem is when I scan these files of code:
./main.js:
```javascript
(() => {})(), // this line makes the codeql neglect the vulnerability?
(() => {
let fe = require('./source.js').s;
let e = fe();
window.location.href = e;
})();
```
./source.js:
```javascript
module.exports.s = function() {
let e = window.location.href.split("#")[1];
return decodeURIComponent(e);
};
```
CodeQL doesn't report any vulnerability but if I comment the first line of main.js, like:
```javascript
// (() => {})(),
(() => {
let fe = require('./source.js').s;
let e = fe();
window.location.href = e;
})();
```
It detected one, which is:
```csv
"Client-side URL redirect","Client-side URL redirection based on unvalidated user input may cause redirection to malicious web sites.","error","Untrusted URL redirection depends on a [[""user-provided value""|""relative:///source.js:2:11:2:30""]].
Untrusted URL redirection depends on a [[""user-provided value""|""relative:///source.js:2:11:2:25""]].","/main.js","5","26","5","26"
```

Is there an issue? Since the part of code `(() => {})()` which seems irrelevant to the vulnerability to me affects the query result.

The version of the codeql that I use:
```bash
CodeQL command-line toolchain release 2.18.3.
Copyright (C) 2019-2024 GitHub, Inc.
Unpacked in: ...
Analysis results depend critically on separately distributed query and
extractor modules. To list modules that are visible to the toolchain,
use 'codeql resolve qlpacks' and 'codeql resolve languages'.
```

And here is the command I use:
```bash
codeql database create --language=javascript codeql-database --source-root="./sourcecode"
codeql database analyze ./codeql-database/ $CODE_QL/codeql-repo/javascript/ql/src/Security/CWE-601/ClientSideUrlRedirect.ql --format=csv --output="result.csv" --threads=10
cat result.csv | grep redirect
```

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。