github / github/codeql

General issue: Missing vulnerability reports due to incomplete self variable reference relationships in Python classes

Offen
#18,374 4 Kommentare 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen
Python question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

code:
```
import os
from flask import Flask, request

app = Flask(__name__)

class CCC:
def update(self, **kwargs):
os.system(kwargs["mode"])

class test:
def __init__(self):
self.A = CCC()

@app.route('/execute')
def execute_command(self):
cmd = request.args.get('cmd')
self.A.update(mode=cmd, file="a")
return "Command executed"
```
ql:
```
/**
* @name Uncontrolled command line
* @description Using externally controlled strings in a command line may allow a malicious
* user to change the meaning of the command.
* @kind path-problem
* @problem.severity error
* @security-severity 9.8
* @sub-severity high
* @precision high
* @id py/command-line-injection
* @tags correctness
* security
* external/cwe/cwe-078
* external/cwe/cwe-088
*/

import python
import semmle.python.security.dataflow.CommandInjectionQuery
import CommandInjectionFlow::PathGraph

from CommandInjectionFlow::PathNode source, CommandInjectionFlow::PathNode sink
where CommandInjectionFlow::flowPath(source, sink)
select sink.getNode(), source, sink, "This command line depends on a $@.", source.getNode(),
"user-provided value"
```
this ql file can not find bug!!!!???
why???
I hope you can help me, thank you.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Reproduce the supplied Python/Flask example with the included CodeQL query, then inspect the dataflow behavior for the self.A.update(...) call and os.system sink. Done means the query reports the command-injection path in this example; no repository file or test is named in the issue.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
flask, python
Bereich
security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
30/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.