github / github/codeql

Javascript Taint Tracking

Offen
#18,765 5 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

I have the following code:

source.js:
```js
function id(mod) {
return mod;
}

function __importDefault(mod) {
return mod && mod.__esModule
? mod
: {
default: mod,
}
}
var sinkMod0 = __importDefault(require("./sink"))
var sinkMod1 = require("./sink")
var sinkMod2 = id(require("./sink"))
var sinkMod3 = unknown(require("./sink"))

function source(s) {
sinkMod0.default(s)
sinkMod1(s)
sinkMod2(s)
sinkMod3(s)
}
```

sink.js:
```js
module.exports = function (data) {
sink(data)
}
```

I am using the following query to get all calls to `sink` from the source function:
```ql
/**
* @kind path-problem
*/

import javascript
import semmle.javascript.dataflow.TaintTracking

module Config implements DataFlow::ConfigSig {
DataFlow::FlowFeature getAFeature() { result instanceof DataFlow::FeatureHasSourceCallContext }

predicate isSource(DataFlow::Node source) {
exists(Function f |
f.getName() = "source" and
source.asExpr() = f.getAParameter()
)
}

predicate isSink(DataFlow::Node node) {
exists(DataFlow::CallNode cn |
cn.getAnArgument() = node and
cn.getCalleeName() = "sink"
)
}
}

module Flow = DataFlow::Global;

import Flow::PathGraph

from Flow::PathNode source, Flow::PathNode sink
where Flow::flowPath(source, sink)
select sink.getNode(), source, sink, ""
```

The above query doesnt find the flow through `sinkMod3(s)` . Is there a way to get codeQL to treat the `unknown(..)` function as an identity function?

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with the supplied source.js, sink.js, and query, then inspect the taint-tracking entry points imported from semmle.javascript.dataflow.TaintTracking. Compare the reported flows through sinkMod0, sinkMod1, and sinkMod2 with the missing sinkMod3 path. Done means the query can report the flow through unknown(require("./sink")) when unknown is intended to behave as an identity function.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
javascript
Bereich
security
Issue-Typ
Feature
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.