github / github/codeql

General issue

未关闭
#4,843 4 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question Stale
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

**Dataflow Bug: codeql javascript Dataflow break with normal parameter (like function a({data1,data2,data3})) pass**

Hello Cool Codeql Guys, i have found a bug when i use dataflow to analyse my javascript with taintpath.

my taintpath query code is normal code just like this:
`
from RiskTaint cfg, PathNode source, PathNode sink
`
`
where cfg.hasFlowPath(source, sink)
`
`
select sink.getNode(), source, sink, "risk funcation call with user-controlled input."
`
however , when i try to analyse the test code is like this:
`
function func_a(param_a){
`
`
local_a=param_a.aaa
`
`
... ...
`
`
const { var_a } = await var_b.method_c({local_a,var_c}) // line a: not correctly get the taint path
`
`
//const { var_a } = await var_b.method_c(local_a,var_c) // line b: correctly get the taint path
`
`
... ...
`
`
}
`
when i use line a to build the query database and analyse taint path , i can't get the taint path from param_a to local_a which was an argument of var_b.method_c,then i try to change line a to line b and it works,so i think it may be the dataflow bug in codeql javascript.

Thks a lot for dealing with my issue,i think codeql is a really really great cool artwork !!!

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。