github / github/codeql

[C++] [Question] How to detect taint on elements in a collection

未关闭
#18,098 8 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

I am trying to detect the flow into `potential_leak` in the following, simplified code. This is just the minimal example, the vector can be constructed any way, e.g. with a series if `push_back` or via iterator etc and I’m trying to find a way to reliably detect taint on any elements at the sink location. Also assume that I do not have access to the source code of `potential_leak` and thus could detect the taint when the elements are accessed.

```cpp
std::vector v { sensitive_data };
potential_leak(v);
```

My simplified query is

```ql
import cpp
import semmle.code.cpp.dataflow.new.TaintTracking

module TaintConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
exists(VariableAccess v |
v.getTarget().getName() = "sensitive_data"
}
}

predicate isSink(DataFlow::Node sink) {
exists(Call c |
c.getTarget().getName() = "potential_leak" and
c.getArgument(0) = e
)
}
}

module Flow = TaintTracking::Global;

from DataFlow::Node src, DataFlow::Node sink
where Flow::flow(src, sink)
select src, sink
```

However this does not detect the flow. Is there some way to select the elements inside of `v` as sinks for this query?

CodeQL version: 2.19.3

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。