github / github/codeql

CWE(s) in Kotlin not being detected by java-kotlin queries?

Open
#19,517 1 comment 0 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

Hi!

I recently did a test with CodeQL on a new Kotlin project, and I included [CWE-1204](https://codeql.github.com/codeql-query-help/java/java-static-initialization-vector/) to get a detection.

I copied the example from documentation and [test case](https://github.com/github/codeql/blob/60cc63f4d4f6827ec68584b8ec0763ed4043189e/java/ql/test/query-tests/security/CWE-1204/StaticInitializationVector.java#L15). I then used IntelliJ IDEA to convert it from Java to Kotlin.

```kotlin
@Throws(Exception::class)
fun encryptWithZeroStaticIvByteArray(key: ByteArray?, plaintext: ByteArray?): ByteArray {
val iv = ByteArray(16) // $Source

val ivSpec = GCMParameterSpec(128, iv)
val keySpec = SecretKeySpec(key, "AES")

val cipher = Cipher.getInstance("AES/GCM/PKCS5PADDING")
cipher.init(Cipher.ENCRYPT_MODE, keySpec, ivSpec) // $Alert
cipher.update(plaintext)
return cipher.doFinal()
}
```

I got no detections, and assumed it was an issue with Actions setup, after debugging I decided to test out [CWE-117](https://codeql.github.com/codeql-query-help/java/java-log-injection/) which I've heard works on Kotlin. After I ran the CI/CD setup it was detected.

I was recommended to try out example from [CWE-1204](https://codeql.github.com/codeql-query-help/java/java-static-initialization-vector/) using a new Java project. After running the CI/CD setup, it was detected.

I spent some time trying to figure out why, decompiling the code, looking at logs. I then looked at sarif file, and I found following rule:

```json
"ruleId": "java/telemetry/unsupported-external-api",
"value": 4,
"message": { "text": "kotlin.ByteArray#ByteArray(int)" }
```

Questions:
* Is there a known list which queries have been tested and works with Kotlin?
* or a list of queries that is not working with Kotlin?
* Is there anything I can do while waiting for queries to be fully compatible with Kotlin?__

Contributor guide

Open the contributing guide

Research direction

Start with the CWE-1204 query help and its linked test at java/ql/test/query-tests/security/CWE-1204/StaticInitializationVector.java, then compare that Java case with the Kotlin example in the issue. Inspect the SARIF entry for java/telemetry/unsupported-external-api and determine whether Kotlin ByteArray handling is covered. Done means establishing the compatibility gap and identifying the required query or documentation change.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, kotlin
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.