github / github/codeql

Need help on JNDI injection query, does not work for log4j test project

Abierto
#7,621 17 comentarios 0 reacciones 0 asignados Ver en GitHub
question
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

I've created a simple log4j project: [log4j-test.zip](https://github.com/github/codeql/files/7886955/log4j-test.zip)

It uses log4j 2.11 which is vulnerable to JNDI injection, and I've verified the vulnerability exists. Now I need to verify codeql also works. So I created the java database with:

```
codeql database create java-database -l=java -c="mvn clean install -file pom.xml" --overwrite
```

Then I opened the starter project and uses `ql/java/ql/src/Security/CWE/CWE-074/JndiInjection.ql` to test it, but no results came out.

![screenshot 2022-01-18 at 3 23 32 PM](https://user-images.githubusercontent.com/1357701/149889753-52e8750f-8815-454d-9011-ca22f9b7410e.jpg)

What was wrong?

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.