java/ssrf: allowlist guard not recognized when expressed via Stream/lambda (anyMatch), only via plain equals()/for-loop
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 45/100
Direzione di ricerca
Inizia con la query java/ssrf e la libreria condivisa sanitizer-guard che utilizza; esamina come vengono modellate le forme esistenti di equals() e dei loop. Aggiungi la copertura di regressione per gli esempi Arrays.stream(...).anyMatch(...), method-reference e contains(...), e verifica che i controlli allowlist riconosciuti cancellino l'alert SSRF senza indebolire gli altri casi.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Query
java/ssrf (Server-side request forgery), Java/Kotlin Security/CWE-918
Summary
The SSRF sanitizer-guard recognition for this query does not appear to model an allowlist check expressed via Arrays.stream(...).anyMatch(...) (or other Stream/lambda/method-reference based equality checks) as taint-clearing, even though a functionally identical check written as a plain for loop with .equals()/.equalsIgnoreCase() calls is recognized and clears the alert.
Example (not recognized — alert fires)
private static boolean isAllowedHost(String host, String... allowedHosts) {
return Arrays.stream(allowedHosts).anyMatch(host::equalsIgnoreCase);
}
void fetch(String userUrl) {
URI uri = new URI(userUrl);
if (isAllowedHost(uri.getHost(), "example.com")) {
uri.toURL().openConnection(); // still flagged as SSRF sink
}
}
Example (recognized — alert clears)
private static boolean isAllowedHost(String host, String... allowedHosts) {
for (String allowed : allowedHosts) {
if (allowed.equalsIgnoreCase(host)) {
return true;
}
}
return false;
}
(Identical behavior/contract; only the loop construct differs.)
Why this matters
Lambda-based and Stream-based collection idioms (anyMatch, Set.of(...).contains(...), etc.) have been idiomatic, widely-used Java since Java 8 (2014). A sanitizer-guard recognizer that only matches a narrow inline if (LITERAL.equals(x))/plain-loop shape — and not equivalent Stream/lambda forms — produces false positives that push teams toward less readable, less idiomatic code purely to satisfy the analyzer, with no corresponding security benefit. This also seems inconsistent with sanitizer/guard modeling in other CodeQL queries that do recognize Collection.contains(...)-style checks.
Ask
Could the java/ssrf (and ideally the shared sanitizer-guard library used across similar taint-tracking queries) be extended to recognize equality-based allowlist checks expressed via common Stream/lambda idioms (Arrays.stream(...).anyMatch(x::equals), Collection.contains(x), Set.of(...).contains(x)) as taint-clearing guards, equivalent to their imperative-loop counterparts?
Happy to provide a minimal reproducible test case/repo if useful.
- Lingua principale
- CodeQL
- Stelle
- 10.1k
- Fork
- 2.1k
- Merge medio
- 2g 11h
- PR unite (30g)
- 129
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di github/codeql
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
-
C#: cs/simplifiable-boolean-expression false positive on Nullable<bool> compared with a literal Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
-
false-positive
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
False positive Apertafalse-positive
Difficoltà 4/5 3-5 giorni Idoneità per principianti 15/100
Tutte le issue di github/codeql
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 90/100
duckdb/duckdb-python#627 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
phpstan/phpstan-doctrine#794 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 78/100
nearform/ag-grid-url-sync#160 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
idean3885/claude-ops-agent#521 ·