github / github/codeql

log4jJndiInjection UserInput instead of RemoteFlowSource

Offen
#7,411 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Java question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

**Description of the issue**
CVE-2021-44228 is affecting a lot of devices in these days. I have that interesting codeql query has been added to detect log4j injections:
https://github.com/github/codeql/blob/main/java/ql/src/experimental/Security/CWE/CWE-020/Log4jJndiInjection.ql

`RemoteFlowSource` instance type is used to detect the source data.
As log4j library is extensively used not only in Spring Applications, do not you think that it could be more useful to use a generic data source such as `UserInput`?
The following vulnerable code:
```java
package logger;

import org.apache.logging.log4j.LogManager;
import org.apache.logging.log4j.Logger;

public class App {
private static final Logger logger = LogManager.getLogger(App.class);
static void logging(String[] args) {
String msg = (args.length > 0 ? args[0] : "");
logger.error(msg);
}
public static void main(String[] args) {
System.out.println("In main");
logging(args);
}
}
```
will not be detected by using:
```java
override predicate isSource(DataFlow::Node source) { source instanceof RemoteFlowSource }
```
But it will be detected by using:
```java
override predicate isSource(DataFlow::Node source) { source instanceof UserInput }
```

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.