github / github/codeql

CodeQL analysis does not detect expected command injection vulnerability

未關閉
#19,811 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Hello CodeQL team**,

I'm currently integrating CodeQL into our CI workflow for an end-to-end security test of our backend system.

Here's the procedure I followed:

Setup:
**Downloaded the CLI:**
wget https://github.com/github/codeql-cli-binaries/releases/latest/download/codeql-linux64.zip
unzip codeql-linux64.zip
sudo mv codeql /usr/local/bin/

**Cloned the CodeQL repository with Python libraries:**
git clone https://github.com/github/codeql.git

**Inside the backend directory, created the database:**
codeql database create db-python --language=python --source-root=.

**Ran the analysis:**
codeql database analyze db-python codeql/python/ql/src/codeql-suites/python-lgtm-full.qls --format=sarifv2.1.0 --output=python-code-scanning-sec-all.sarif

**Checked the results:**
jq '.runs[].results[] | {message: .message.text, severity: .level, location: .locations[0].physicalLocation.artifactLocation.uri}' python-code-scanning-sec-all.sarif

**Problem**
Before running the scan, I added the following code snippet to the backend intentionally to trigger a command injection warning:

```
import os
user_input = input("Enter command: ")
os.system(user_input) # ⚠️ This should trigger a CodeQL rule: command injection
```
However, the scan results do not include any findings related to this vulnerable code.

**Question**
Am I missing something in the setup or the suite configuration?
Is there a different CodeQL query or suite that should be used to detect this specific type of vulnerability (e.g., command injection via os.system) in Python?

Any help or guidance would be much appreciated!

Best regards,
Anton

貢獻指南

開啟貢獻指南

研究方向

Reproduce the report with the shown Python snippet, the db-python database, and codeql/python/ql/src/codeql-suites/python-lgtm-full.qls. Inspect the generated python-code-scanning-sec-all.sarif results and the suite configuration to determine why no finding appears. Done means identifying the cause and documenting the required query or setup for detecting this case.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
python
領域
security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
需要釐清
新手友好度
30/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。