False positive: CWE-918
- 主要语言
- CodeQL
- 星标
- 10.1k
- 派生
- 2.1k
- 平均合并
- 2 天 15 小时
- 30 天内合并 PR
- 141
描述
Test case:
```go
package main
import (
"net/http"
"net/url"
)
func testssrf(req *http.Request) {
host := req.URL.Query().Get("host")
u, _ := url.Parse("http://example")
// The current value of u is "http://example"
http.Get(u.String()) // Expected: negative Actual: positive
u.Host = host
http.Get(u.String())
}
```
The following code may have caused the false positives.
codeql-go/ql/src/semmle/go/security/RequestForgery.qll
```ql
override predicate isAdditionalTaintStep(DataFlow::Node pred, DataFlow::Node succ) {
// propagate to a URL when its host is assigned to
exists(Write w, Field f, SsaWithFields v | f.hasQualifiedName("net/url", "URL", "Host") |
w.writesField(v.getAUse(), f, pred) and succ = v.getAUse()
)
}
```
贡献指南
评估
这个 Issue 还没有评估数据。