github / github/codeql

[Python][Questions] CodeQL security query is not able to detect CWE from given bad example in repository.

Open
#8,555 0 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

I have created codeql database of this python file [https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/examples/tarslip_bad.py](https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/examples/tarslip_bad.py).
But when I analyze database using [https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/TarSlip.ql](https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/TarSlip.ql) this query, I see nothing in query results.

Can someone help me why codeql query is not able to detect CWE-22 from the given example?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.