[JS] False Negative : Unsafe Html Construction
- 主要言語
- CodeQL
- スター
- 10.1k
- フォーク
- 2.1k
- 平均マージ
- 2日 15時間
- マージ済み PR(30日)
- 141
説明
In the following snippet, only the middle snippet is returned as vulnerable (the first and third calls are not marked vulnerable).
For the first case, I assume that _escaping_ single or double quotes will make the code safe. But in the third code snippet, it only _escapes_ `"` and should still be marked vulnerable? It seems that
* the query only detects `attrVal.indexOf("\"") === -1` as a guard (and does not even consider `attrVal.indexOf("'") === -1` as a guard)
* does not use flow labels to check if both guards exist
```js
module.exports.guards = function(attrVal) {
if (attrVal.indexOf("\"") === -1 && attrVal.indexOf("'") === -1) {
document.querySelector("#id").innerHTML = ""; // OK [not reported vulnerable]
}
if (attrVal.indexOf("'") === -1) {
document.querySelector("#id").innerHTML = ""; // NOT OK [reported vulnerable]
}
if (attrVal.indexOf("\"") === -1) {
document.querySelector("#id").innerHTML = ""; // NOT OK [not reported vulnerable] [False Negative?]
}
}
```
コントリビューションガイド
評価
この issue はまだ評価されていません。