github / github/codeql

The strings were concatenated, making it impossible to match the path.

Đang mở
#19,479 4 bình luận 0 reaction 0 người được giao Xem trên GitHub
question
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

Source can query the fileName.
![Image](https://github.com/user-attachments/assets/be6b5bb4-8bf2-473e-8ec7-8473f65aed09)
Sink can also query data.
![Image](https://github.com/user-attachments/assets/0bb4c178-36e3-49a9-9866-31b3b578fb8d)
Logic can be connected.
![Image](https://github.com/user-attachments/assets/b0066f0d-42c9-4597-b37b-bfc10f14d6ef)
But no results were found.
![Image](https://github.com/user-attachments/assets/83905e7f-0c2b-49ad-a946-f7b9edd55b53)
The test from fileName to FileUtils.isValidFilename can retrieve results.
![Image](https://github.com/user-attachments/assets/62a80658-e043-449d-9497-19b0b0b5d12f)
However, when querying from fileName to writeBytes, no results are returned. The data passes through the line "String filePath = Global.getDownloadPath() + fileName;" in the middle.

![Image](https://github.com/user-attachments/assets/afec0902-6c54-4297-a185-9cda90eb2087)

![Image](https://github.com/user-attachments/assets/00b657c6-ee6c-427c-bdca-de738f941534)

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Start by tracing the reported flow from fileName through "String filePath = Global.getDownloadPath() + fileName;" to writeBytes, and compare it with the path to FileUtils.isValidFilename. Inspect how the CodeQL data-flow query handles the concatenation, then verify that the fileName-to-writeBytes query returns a result while the existing path remains covered.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
java
Lĩnh vực
security
Loại issue
Lỗi
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.