[Python][Questions] CodeQL security query is not able to detect CWE from given bad example in repository.
Đang mở
question
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 141
Mô tả
I have created codeql database of this python file [https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/examples/tarslip_bad.py](https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/examples/tarslip_bad.py).
But when I analyze database using [https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/TarSlip.ql](https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/TarSlip.ql) this query, I see nothing in query results.
Can someone help me why codeql query is not able to detect CWE-22 from the given example?
Hướng dẫn đóng góp
Đánh giá
Issue này chưa được đánh giá.