github / github/codeql

LGTM.com - false positive - Java - Netty Response Splitting

Abierto
#2,908 0 comentarios 0 reacciones 0 asignados Ver en GitHub
false-positive Java
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Description of the false positive**

When the `DefaultFullHttpResponse` is used in a limited scope where it's provable that no headers are added from sources other than static locations, this is a safe place where verification is safe to disable.

Since this query already gets so few hits, I think that it's safe to continue to flag all other cases, even when QL can't prove that user supplied data flows to netty because many libraries are simply wrappers for netty so wouldn't directly show data flow from user supplied data.

**URL to the alert on the project page on LGTM.com**

- https://lgtm.com/projects/g/eclipse-vertx/vert.x/snapshot/229594b9c483132e6efa5c24f66f826a990b53de/files/src/main/java/io/vertx/core/http/impl/Http1xUpgradeToH2CHandler.java?sort=name&dir=ASC&mode=heatmap#L83
- https://lgtm.com/projects/g/eclipse-vertx/vert.x/snapshot/229594b9c483132e6efa5c24f66f826a990b53de/files/src/main/java/io/vertx/core/http/impl/Http1xUpgradeToH2CHandler.java?sort=name&dir=ASC&mode=heatmap#L113

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.