github / github/codeql

codeql js taint tracking - write "recursive" additional taint step

Offen
#19,098 2 Kommentare 0 Reaktionen 1 zugewiesene Person Beansprucht von @mbg Auf GitHub ansehen
javascript question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

I have the following code:
```js
function source() {
fn0();
fn1();
}

function fn0() {
const a = process.env.SECRET;
sink(a);
}

function fn1() {
fn0();
}
```

In this example everything coming from the env is tainted. However, I do not want to find a taint path that starts at `fn0` (where we have the env propread), but from `source`.

I came up with the following config that uses `isAdditionalFlowStep` to check whether the current function has a call to a function where an env propread is made:

```ql
module Config implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
exists(Function f |
f.getName() = "source" and
(
source.asExpr() = f.getAParameter()
or
source.(DataFlow::FunctionNode).getFunction() = f
)
)
}

predicate isSink(DataFlow::Node node) {
exists(DataFlow::CallNode cn |
cn.getAnArgument() = node and
cn.getCalleeName() = "sink"
)
}

predicate isAdditionalFlowStep(DataFlow::Node fromNode, DataFlow::Node toNode) {
exists(DataFlow::FunctionNode fnEnv, DataFlow::PropRead propRead |
propRead = toNode and
propRead.getPropertyName() = "SECRET" and
propRead.asExpr().getEnclosingFunction() = fnEnv.getFunction() and
fromNode.(DataFlow::InvokeNode).getACallee() = fnEnv.getFunction()
)
or
toNode.(DataFlow::InvokeNode).getEnclosingFunction() =
fromNode.(DataFlow::FunctionNode).getFunction()
}
}
```

This finds the taint path `source` -> `fn0`, but not `source`->`fn1`->`fn0`.
I am not sure how to restructure the predicate to introduce these taint steps in a recursive manner.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.