github / github/codeql

UnvalidatedDynamicMethodCall query does not detect flow inside try/catch

未關閉
#20,098 3 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

Hi CodeQL team 👋

I'm currently building some training challenges for developers to help them identify insecure dynamic method calls. I designed one of the [exercises](https://github.com/fguisso/backoffice-balm) based on the `UnvalidatedDynamicMethodCall` alert.

However, I noticed that the vulnerability I created was not detected by the query. After a lot of debugging, I suspect the query does not handle taint flow properly when the logic is inside arrow functions.

- The vulnerable code uses an Express route with an arrow function as the handler.
- Inside the arrow function, I access `req.params.action` and use it to dynamically invoke a method: `userManager[action](...)`.
- This allows access to both regular and admin-only methods of the userManager object.

Unfortunately, this pattern wasn't flagged by the query, even though it's clearly unsafe.

I'm still learning how CodeQL queries work, and I'm not very experienced with the query language yet. I'd really appreciate any help understanding why this scenario is missed, and how I might contribute a feature for it.

I'd love to open a PR — just need some guidance on how to proceed the right way.

`update`: I have tested here like @rvermeulen said and the catch is the `try/catch`.

`git blaming` cc: @asgerf

貢獻指南

開啟貢獻指南

研究方向

從 UnvalidatedDynamicMethodCall 查詢開始,並重現 issue 中連結的訓練挑戰。比較使用 req.params.action 的 Express 路由在 arrow-function 處理常式中有無 try/catch 時的情況,然後確認在 issue 修正後可以偵測到存在漏洞的動態呼叫。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
express, javascript
領域
security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。