Remediation advice in SSRF could be more broadly focused
- Lenguaje dominante
- CodeQL
- Estrellas
- 10.1k
- Forks
- 2.1k
- Merge medio
- 2 d 15 h
- PR fusionados (30 d)
- 141
Descripción
**Description of the issue**
The [remediation advice for how to mitigate SSRF vulnerabilities ](https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-918/ServerSideRequestForgery-end.inc.qhelp#L7) is focused on URL allowlisting. While this is fairly good for https schemes where possible to implement, it's not really a comprehensive defense for SSRF.
The advice given assumes that an attacker can't manipulate DNS entries for the domain being allowlisted. It also doesn't offer any advice for mitigating SSRF if an attacker has complete control of the URL and an allowlist isn't practical.
It would be good to add a sentence to the advice to make the remediation advice less specific. Perhaps incorporating a mention of additional network or application controls to prevent servers from making connections to internal resources in the first place (e.g. based on IP addresses).
https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/
Guía de contribución
Línea de trabajo
Comienza con python/ql/src/Security/CWE-918/ServerSideRequestForgery-end.inc.qhelp en las recomendaciones de remediación enlazadas en el issue y, a continuación, compáralas con las directrices de OWASP sobre SSRF. Amplía las recomendaciones más allá de la inclusión de URL en una allowlist para mencionar controles de red o de aplicación adicionales, y verifica que el texto final aborde tanto las URL incluidas en la allowlist como las controladas por un atacante.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Área
- documentation, security
- Tipo de issue
- Documentación
- Dificultad
- 1/5
- Tiempo estimado
- 1-3 horas
- Estado de actividad
- Estancado
- Claridad
- Bien especificado
- Aptitud para principiantes
- 45/100