[Java] CWE-117: CodeQL query to detect Log Injection
- Langage dominant
- C
- Étoiles
- 1.6k
- Forks
- 300
- Métriques de merge des PR
- Aucune PR mergée en 30 j
Description
## CVE ID(s)
*List the CVE ID(s) associated with this vulnerability. GitHub will automatically link CVE IDs to the [GitHub Advisory Database](https://github.com/advisories).*
- There is no CVE for this.
## Report
Log Injection query is available in c# query, javascript (experimental) query but it is not available in java query.
I created a query to detect a log injection vulnerability in java code.
Link to the PR: PR github/codeql#3882
- [X] Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc). *We would love to have you spread the word about the good work you are doing*
## Result(s)
The query was able to detect a potential Log Forging (now fixed) in the `generator-jhipster` project.
This is the PR fixing the potential Log Forging: [prevent potential log forging](https://github.com/jhipster/generator-jhipster/pull/11708), and here the fixed code [https://github.com/jhipster/generator-jhipster/pull/11708/files](https://github.com/jhipster/generator-jhipster/pull/11708/files).
To test the query, I used the vulnerable version of that file. I created a project using `jhipster` ([Creating an application](https://www.jhipster.tech/creating-an-app/)), and then I run the query on the project already created; the query was able to detect the vulnerability mentioned in the PR (once I created the project, before generating the database, I replaced the fixed code, with its previous version).
There is also a CVE (another project): [CVE-2020-4072: Log Forging in generator-jhipster-kotlin](https://github.com/advisories/GHSA-pfxf-wh96-fvjc), that mentions the equivalent `java` file of the `generator-jhipter` project: [commit: prevent log forging when doing password reset init request](https://github.com/jhipster/jhipster-kotlin/commit/426ccab85e7e0da562643200637b99b6a2a99449).
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Examinez les requêtes existantes en C# et les requêtes expérimentales en JavaScript pour log-injection, puis inspectez la requête proposée dans la PR github/codeql#3882. Reproduisez la vérification avec le code vulnérable de generator-jhipster décrit dans l’issue ; le travail est terminé lorsque la requête Java détecte le flux de log-forging signalé.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- java
- Domaine
- security
- Type d'issue
- Fonctionnalité
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- À l'abandon
- Clarté
- Plutôt claire
- Accessibilité débutants
- 25/100