github / github/codeql

General issue

未關閉
#4,843 4 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question Stale
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Dataflow Bug: codeql javascript Dataflow break with normal parameter (like function a({data1,data2,data3})) pass**

Hello Cool Codeql Guys, i have found a bug when i use dataflow to analyse my javascript with taintpath.

my taintpath query code is normal code just like this:
`
from RiskTaint cfg, PathNode source, PathNode sink
`
`
where cfg.hasFlowPath(source, sink)
`
`
select sink.getNode(), source, sink, "risk funcation call with user-controlled input."
`
however , when i try to analyse the test code is like this:
`
function func_a(param_a){
`
`
local_a=param_a.aaa
`
`
... ...
`
`
const { var_a } = await var_b.method_c({local_a,var_c}) // line a: not correctly get the taint path
`
`
//const { var_a } = await var_b.method_c(local_a,var_c) // line b: correctly get the taint path
`
`
... ...
`
`
}
`
when i use line a to build the query database and analyse taint path , i can't get the taint path from param_a to local_a which was an argument of var_b.method_c,then i try to change line a to line b and it works,so i think it may be the dataflow bug in codeql javascript.

Thks a lot for dealing with my issue,i think codeql is a really really great cool artwork !!!

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。