github / github/codeql

[C++] [Question] How to detect taint on elements in a collection

Abierto
#18,098 8 comentarios 0 reacciones 0 asignados Ver en GitHub
question
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

I am trying to detect the flow into `potential_leak` in the following, simplified code. This is just the minimal example, the vector can be constructed any way, e.g. with a series if `push_back` or via iterator etc and I’m trying to find a way to reliably detect taint on any elements at the sink location. Also assume that I do not have access to the source code of `potential_leak` and thus could detect the taint when the elements are accessed.

```cpp
std::vector v { sensitive_data };
potential_leak(v);
```

My simplified query is

```ql
import cpp
import semmle.code.cpp.dataflow.new.TaintTracking

module TaintConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
exists(VariableAccess v |
v.getTarget().getName() = "sensitive_data"
}
}

predicate isSink(DataFlow::Node sink) {
exists(Call c |
c.getTarget().getName() = "potential_leak" and
c.getArgument(0) = e
)
}
}

module Flow = TaintTracking::Global;

from DataFlow::Node src, DataFlow::Node sink
where Flow::flow(src, sink)
select src, sink
```

However this does not detect the flow. Is there some way to select the elements inside of `v` as sinks for this query?

CodeQL version: 2.19.3

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.