github / github/codeql

Missing "Cross-window communication with unrestricted target origin" because of wrapping by (javascript) blockstatement

Offen
#19,100 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
acknowledged question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

Hi,

I am using CodeQL 2.20.6, there is the code:
```js
// {
const t = {};
const r = localStorage.getItem("pw_uuid");
r && JSON.parse(r).data && (t.uuid = JSON.parse(r).data);
window.parent.postMessage(JSON.stringify({
type: "_pwUserDataReady",
key: "",
data: t
}), "*");
// }
```
Where CodeQL should give me a "Cross-window communication with unrestricted target origin" alert but it doesn't.

If I remove the first and last line comments, i.e., wrapping by a block as the code is:
```js
{
const t = {};
const r = localStorage.getItem("pw_uuid");
r && JSON.parse(r).data && (t.uuid = JSON.parse(r).data);
window.parent.postMessage(JSON.stringify({
type: "_pwUserDataReady",
key: "",
data: t
}), "*");
}
```

It does give me one:
```csv
"Cross-window communication with unrestricted target origin", "When sending sensitive information to another window using `postMessage`, the origin of the target window should be restricted to avoid unintentional information leaks.", "error","[[""Sensitive data""|""relative:///iframe.js:3:15:3:45""]] is sent to another window without origin restriction.","/iframe.js", "5", "31", "9", "6"
```

This issue looks the same with but it should be fixed in 2.20.6, shouldn't it?

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Reproduce the report in CodeQL 2.20.6 using the two JavaScript variants, with and without the block wrapper, and compare the results at the reported /iframe.js locations. Read related issue #18652 for context. Done means the unrestricted postMessage is reported in both forms, or the supported limitation is documented.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
javascript
Bereich
security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.