github / github/codeql

log4jJndiInjection UserInput instead of RemoteFlowSource

Abierto
#7,411 1 comentario 0 reacciones 0 asignados Ver en GitHub
Java question
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Description of the issue**
CVE-2021-44228 is affecting a lot of devices in these days. I have that interesting codeql query has been added to detect log4j injections:
https://github.com/github/codeql/blob/main/java/ql/src/experimental/Security/CWE/CWE-020/Log4jJndiInjection.ql

`RemoteFlowSource` instance type is used to detect the source data.
As log4j library is extensively used not only in Spring Applications, do not you think that it could be more useful to use a generic data source such as `UserInput`?
The following vulnerable code:
```java
package logger;

import org.apache.logging.log4j.LogManager;
import org.apache.logging.log4j.Logger;

public class App {
private static final Logger logger = LogManager.getLogger(App.class);
static void logging(String[] args) {
String msg = (args.length > 0 ? args[0] : "");
logger.error(msg);
}
public static void main(String[] args) {
System.out.println("In main");
logging(args);
}
}
```
will not be detected by using:
```java
override predicate isSource(DataFlow::Node source) { source instanceof RemoteFlowSource }
```
But it will be detected by using:
```java
override predicate isSource(DataFlow::Node source) { source instanceof UserInput }
```

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.