log4jJndiInjection UserInput instead of RemoteFlowSource
- 主要言語
- CodeQL
- スター
- 10.1k
- フォーク
- 2.1k
- 平均マージ
- 2日 15時間
- マージ済み PR(30日)
- 141
説明
**Description of the issue**
CVE-2021-44228 is affecting a lot of devices in these days. I have that interesting codeql query has been added to detect log4j injections:
https://github.com/github/codeql/blob/main/java/ql/src/experimental/Security/CWE/CWE-020/Log4jJndiInjection.ql
`RemoteFlowSource` instance type is used to detect the source data.
As log4j library is extensively used not only in Spring Applications, do not you think that it could be more useful to use a generic data source such as `UserInput`?
The following vulnerable code:
```java
package logger;
import org.apache.logging.log4j.LogManager;
import org.apache.logging.log4j.Logger;
public class App {
private static final Logger logger = LogManager.getLogger(App.class);
static void logging(String[] args) {
String msg = (args.length > 0 ? args[0] : "");
logger.error(msg);
}
public static void main(String[] args) {
System.out.println("In main");
logging(args);
}
}
```
will not be detected by using:
```java
override predicate isSource(DataFlow::Node source) { source instanceof RemoteFlowSource }
```
But it will be detected by using:
```java
override predicate isSource(DataFlow::Node source) { source instanceof UserInput }
```
コントリビューションガイド
評価
この issue はまだ評価されていません。