github / github/codeql

False positive: Full server-side request forgery

Offen
#20,093 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
false-positive
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

**Description of the false positive**

I have seen alerts for "Full server-side request forgery" (id: `py/full-ssrf`), even though the code has a valid mitigation in place. CodeQL also isn't recognizing other valid mitigations for this vulnerability.

For example, given this code:

```python
url = request.url.replace(request.host_url, "my-expected-host-url")

resp = requests.request(
url=url,
)
```

As you can see, this code is already using `request.url.replace` to control the requested URL and ensure that malicious requests cannot manipulate the destination of the request. However, CodeQL does not recognize this method as a valid mitigation for SSRF.

I also tried:

```python
from urllib.parse import urljoin

url = urljoin("my-expected-host-url", request.path)
```

CodeQL does not accept this approach either.

The only approach that CodeQL accepts is string concatenation:

```python
url = "my-expected-host-url" + request.path
```

Having to use string concatenation instead of `urljoin` is not ideal.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with the py/full-ssrf query and reproduce the reported Python examples using request.url.replace and urllib.parse.urljoin. Compare their alerts with the accepted string-concatenation example, then verify that valid URL-construction mitigations are recognized without suppressing real SSRF findings.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.