github / github/codeql

[JS] False Negative : Unsafe Html Construction

Aberta
#8,274 7 comentários 0 reações 0 responsáveis Ver no GitHub
JS question
Linguagem predominante
CodeQL
Estrelas
10.1k
Forks
2.1k
Merge médio
2d 15h
PRs com merge (30d)
141

Descrição

In the following snippet, only the middle snippet is returned as vulnerable (the first and third calls are not marked vulnerable).

For the first case, I assume that _escaping_ single or double quotes will make the code safe. But in the third code snippet, it only _escapes_ `"` and should still be marked vulnerable? It seems that
* the query only detects `attrVal.indexOf("\"") === -1` as a guard (and does not even consider `attrVal.indexOf("'") === -1` as a guard)
* does not use flow labels to check if both guards exist

```js
module.exports.guards = function(attrVal) {
if (attrVal.indexOf("\"") === -1 && attrVal.indexOf("'") === -1) {
document.querySelector("#id").innerHTML = "\"""; // OK [not reported vulnerable]
}
if (attrVal.indexOf("'") === -1) {
document.querySelector("#id").innerHTML = "\"""; // NOT OK [reported vulnerable]
}
if (attrVal.indexOf("\"") === -1) {
document.querySelector("#id").innerHTML = "\"""; // NOT OK [not reported vulnerable] [False Negative?]
}
}
```

Guia de contribuição

Abrir o guia de contribuição

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.