github / github/codeql

CWE(s) in Kotlin not being detected by java-kotlin queries?

オープン
#19,517 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
question
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

Hi!

I recently did a test with CodeQL on a new Kotlin project, and I included [CWE-1204](https://codeql.github.com/codeql-query-help/java/java-static-initialization-vector/) to get a detection.

I copied the example from documentation and [test case](https://github.com/github/codeql/blob/60cc63f4d4f6827ec68584b8ec0763ed4043189e/java/ql/test/query-tests/security/CWE-1204/StaticInitializationVector.java#L15). I then used IntelliJ IDEA to convert it from Java to Kotlin.

```kotlin
@Throws(Exception::class)
fun encryptWithZeroStaticIvByteArray(key: ByteArray?, plaintext: ByteArray?): ByteArray {
val iv = ByteArray(16) // $Source

val ivSpec = GCMParameterSpec(128, iv)
val keySpec = SecretKeySpec(key, "AES")

val cipher = Cipher.getInstance("AES/GCM/PKCS5PADDING")
cipher.init(Cipher.ENCRYPT_MODE, keySpec, ivSpec) // $Alert
cipher.update(plaintext)
return cipher.doFinal()
}
```

I got no detections, and assumed it was an issue with Actions setup, after debugging I decided to test out [CWE-117](https://codeql.github.com/codeql-query-help/java/java-log-injection/) which I've heard works on Kotlin. After I ran the CI/CD setup it was detected.

I was recommended to try out example from [CWE-1204](https://codeql.github.com/codeql-query-help/java/java-static-initialization-vector/) using a new Java project. After running the CI/CD setup, it was detected.

I spent some time trying to figure out why, decompiling the code, looking at logs. I then looked at sarif file, and I found following rule:

```json
"ruleId": "java/telemetry/unsupported-external-api",
"value": 4,
"message": { "text": "kotlin.ByteArray#ByteArray(int)" }
```

Questions:
* Is there a known list which queries have been tested and works with Kotlin?
* or a list of queries that is not working with Kotlin?
* Is there anything I can do while waiting for queries to be fully compatible with Kotlin?__

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with the CWE-1204 query help and its linked test at java/ql/test/query-tests/security/CWE-1204/StaticInitializationVector.java, then compare that Java case with the Kotlin example in the issue. Inspect the SARIF entry for java/telemetry/unsupported-external-api and determine whether Kotlin ByteArray handling is covered. Done means establishing the compatibility gap and identifying the required query or documentation change.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
java, kotlin
領域
security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。