github / github/codeql

[C++] [Question] How to detect taint on elements in a collection

未關閉
#18,098 8 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

I am trying to detect the flow into `potential_leak` in the following, simplified code. This is just the minimal example, the vector can be constructed any way, e.g. with a series if `push_back` or via iterator etc and I’m trying to find a way to reliably detect taint on any elements at the sink location. Also assume that I do not have access to the source code of `potential_leak` and thus could detect the taint when the elements are accessed.

```cpp
std::vector v { sensitive_data };
potential_leak(v);
```

My simplified query is

```ql
import cpp
import semmle.code.cpp.dataflow.new.TaintTracking

module TaintConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
exists(VariableAccess v |
v.getTarget().getName() = "sensitive_data"
}
}

predicate isSink(DataFlow::Node sink) {
exists(Call c |
c.getTarget().getName() = "potential_leak" and
c.getArgument(0) = e
)
}
}

module Flow = TaintTracking::Global;

from DataFlow::Node src, DataFlow::Node sink
where Flow::flow(src, sink)
select src, sink
```

However this does not detect the flow. Is there some way to select the elements inside of `v` as sinks for this query?

CodeQL version: 2.19.3

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。