-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Java: Preserve taint on field-read-steps on entrypoint types #6098
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Java: Preserve taint on field-read-steps on entrypoint types #6098
Conversation
java/ql/src/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll
Outdated
Show resolved
Hide resolved
java/ql/src/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll
Outdated
Show resolved
Hide resolved
java/ql/src/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll
Outdated
Show resolved
Hide resolved
java/ql/src/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll
Outdated
Show resolved
Hide resolved
java/ql/test/library-tests/dataflow/entrypoint-types/EntryPointTypesTest.java
Show resolved
Hide resolved
java/ql/src/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll
Outdated
Show resolved
Hide resolved
java/ql/src/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll
Outdated
Show resolved
Hide resolved
aschackmull
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This looks reasonable, but adds quite a number of new steps, so we should check for performance impact.
a58d4cc to
217d14f
Compare
|
Force-pushed to fix conflicts. @aschackmull did the performance evaluation work out? |
|
Looks like we need a rebase to enable a dca run. |
java/ql/lib/semmle/code/java/dataflow/internal/TaintTrackingUtil.qll
Outdated
Show resolved
Hide resolved
3c45d9f to
27f4554
Compare
…il.qll Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com>
27f4554 to
c1e4c05
Compare
|
DCA experiment looks good. I force-pushed to adapt the change note to the new format. |
This PR adds an additional taint step between remote source
Parametertypes (e.g. parameters of aJAX-RSresource method) and field reads on said types (either directly or through getters).Credits to @pwntester for the solution proposal.