-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathremote-to-validate.ql
More file actions
59 lines (52 loc) · 1.89 KB
/
remote-to-validate.ql
File metadata and controls
59 lines (52 loc) · 1.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
/**
* @kind path-problem
*/
import java
import semmle.code.java.dataflow.TaintTracking
import DataFlow::PathGraph
import semmle.code.java.dataflow.FlowSources
class TypeConstraintValidator extends GenericInterface {
TypeConstraintValidator() { hasQualifiedName("javax.validation", "ConstraintValidator") }
}
class CustomStepper extends TaintTracking::AdditionalTaintStep {
override predicate step(DataFlow::Node pred, DataFlow::Node succ) {
// from `a` to `a.b()`
exists(MethodAccess ma |
succ.asExpr() = ma and
pred.asExpr() = ma.getQualifier()
) or
// from `a` to `new Class(a)`
exists(ConstructorCall ma |
succ.asExpr() = ma and
ma.getAnArgument() = pred.asExpr()
) or
// from `a` to `func(a)`: too general
exists(MethodAccess ma |
succ.asExpr() = ma and
pred.asExpr() = ma.getAnArgument()
) or
// forEach handler
exists( LambdaExpr l, MethodAccess ma |
l.asMethod().getAParameter() = succ.asParameter() and
ma.getAnArgument() = l and
ma.getMethod().getName() = "forEach" and
ma.getQualifier() = pred.asExpr()
)
}
}
class MyTaintTrackingConfig extends TaintTracking::Configuration {
MyTaintTrackingConfig() { this = "MyTaintTrackingConfig" }
override predicate isSource(DataFlow::Node source) {
source instanceof RemoteFlowSource
}
override predicate isSink(DataFlow::Node sink) {
exists(MethodAccess c |
sink.asExpr() = c.getAnArgument() and
c.getMethod().hasName("validate") and
c.getMethod().getDeclaringType().hasQualifiedName("com.netflix.titus.common.model.sanitizer", "EntitySanitizer")
)
}
}
from MyTaintTrackingConfig cfg, DataFlow::PathNode source, DataFlow::PathNode sink
where cfg.hasFlowPath(source, sink)
select sink, source, sink, "Custom constraint error message contains unsanitized user data"