github / github/codeql

[C++] [Question] How to detect taint on elements in a collection

オープン
#18,098 コメント 8 件 リアクション 0 件 担当者 0 名 GitHub で見る
question
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

I am trying to detect the flow into `potential_leak` in the following, simplified code. This is just the minimal example, the vector can be constructed any way, e.g. with a series if `push_back` or via iterator etc and I’m trying to find a way to reliably detect taint on any elements at the sink location. Also assume that I do not have access to the source code of `potential_leak` and thus could detect the taint when the elements are accessed.

```cpp
std::vector v { sensitive_data };
potential_leak(v);
```

My simplified query is

```ql
import cpp
import semmle.code.cpp.dataflow.new.TaintTracking

module TaintConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
exists(VariableAccess v |
v.getTarget().getName() = "sensitive_data"
}
}

predicate isSink(DataFlow::Node sink) {
exists(Call c |
c.getTarget().getName() = "potential_leak" and
c.getArgument(0) = e
)
}
}

module Flow = TaintTracking::Global;

from DataFlow::Node src, DataFlow::Node sink
where Flow::flow(src, sink)
select src, sink
```

However this does not detect the flow. Is there some way to select the elements inside of `v` as sinks for this query?

CodeQL version: 2.19.3

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。