[JS] False Negative : Unsafe Html Construction
- Linguagem predominante
- CodeQL
- Estrelas
- 10.1k
- Forks
- 2.1k
- Merge médio
- 2d 15h
- PRs com merge (30d)
- 141
Descrição
In the following snippet, only the middle snippet is returned as vulnerable (the first and third calls are not marked vulnerable).
For the first case, I assume that _escaping_ single or double quotes will make the code safe. But in the third code snippet, it only _escapes_ `"` and should still be marked vulnerable? It seems that
* the query only detects `attrVal.indexOf("\"") === -1` as a guard (and does not even consider `attrVal.indexOf("'") === -1` as a guard)
* does not use flow labels to check if both guards exist
```js
module.exports.guards = function(attrVal) {
if (attrVal.indexOf("\"") === -1 && attrVal.indexOf("'") === -1) {
document.querySelector("#id").innerHTML = ""; // OK [not reported vulnerable]
}
if (attrVal.indexOf("'") === -1) {
document.querySelector("#id").innerHTML = ""; // NOT OK [reported vulnerable]
}
if (attrVal.indexOf("\"") === -1) {
document.querySelector("#id").innerHTML = ""; // NOT OK [not reported vulnerable] [False Negative?]
}
}
```
Guia de contribuição
Avaliação
Esta issue ainda não foi avaliada.