False positive: Go / MongoDB Find method
- 主要言語
- CodeQL
- スター
- 10.1k
- フォーク
- 2.1k
- 平均マージ
- 2日 15時間
- マージ済み PR(30日)
- 141
説明
**Description of the false positive**
**Code samples or links to source code**
https://github.com/github/codeql/blob/dc440aaee6695deb0d9676b87e06ea984e1b4ae5/go/ql/src/Security/CWE-089/SqlInjection/
The following code has a large number of vulnerability false positives in the case of a MongoDB database.
The current MongoDB parameters have defined specific data types, and there are no injection vulnerabilities.
```
type LogFilter struct {
ID []string
}
filter *LogFilter
filterM["id"] = filter.ID
cur, err := dl.Find(ctx, filterM, opts)
```
-->
コントリビューションガイド
調査の方向性
Start by reading the linked Go SQL-injection query and comparing its handling of the MongoDB Find call shown in the sample. Use the typed LogFilter and ID values as the starting case; done means this valid MongoDB usage is no longer reported as an injection false positive.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- go, mongodb
- 領域
- databases, security
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 停滞
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 30/100