github / github/codeql

log4jJndiInjection UserInput instead of RemoteFlowSource

Đang mở
#7,411 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
Java question
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

**Description of the issue**
CVE-2021-44228 is affecting a lot of devices in these days. I have that interesting codeql query has been added to detect log4j injections:
https://github.com/github/codeql/blob/main/java/ql/src/experimental/Security/CWE/CWE-020/Log4jJndiInjection.ql

`RemoteFlowSource` instance type is used to detect the source data.
As log4j library is extensively used not only in Spring Applications, do not you think that it could be more useful to use a generic data source such as `UserInput`?
The following vulnerable code:
```java
package logger;

import org.apache.logging.log4j.LogManager;
import org.apache.logging.log4j.Logger;

public class App {
private static final Logger logger = LogManager.getLogger(App.class);
static void logging(String[] args) {
String msg = (args.length > 0 ? args[0] : "");
logger.error(msg);
}
public static void main(String[] args) {
System.out.println("In main");
logging(args);
}
}
```
will not be detected by using:
```java
override predicate isSource(DataFlow::Node source) { source instanceof RemoteFlowSource }
```
But it will be detected by using:
```java
override predicate isSource(DataFlow::Node source) { source instanceof UserInput }
```

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.