Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
57886e1
Moved files from experimental to src/
egregius313 Mar 2, 2023
5ff4fcb
Replace `exists` with `any`
egregius313 Mar 2, 2023
938d953
Refactor getLeftmostOperand method
egregius313 Mar 3, 2023
9275b54
Refactoring the InsecureLdapUrl constructor
egregius313 Mar 7, 2023
3936aea
Split Ldap query file into libraries
egregius313 Mar 9, 2023
98b445c
Convert test to InlineExpectationsTest
egregius313 Mar 9, 2023
05da1dc
Merge concatInsecureLdapString into InsecureLdapUrl constructor
egregius313 Mar 9, 2023
6a0167f
Convert to using the new DataFlow modules
egregius313 Mar 9, 2023
db60c08
Add security severity
egregius313 Mar 9, 2023
0f4709e
Add change note
egregius313 Mar 9, 2023
59ce0d7
Documentation changes
egregius313 Mar 9, 2023
efdfc2d
Change version of PathNode used to appropriate module
egregius313 Mar 9, 2023
752620a
Rename SSL configuration and fix PathGraph
egregius313 Mar 9, 2023
cb58936
Documentation changes
egregius313 Mar 10, 2023
658c54a
Change names of configuration to fit new naming convention
egregius313 Mar 10, 2023
151357d
Make classes/predicates not used outside of query private
egregius313 Mar 17, 2023
24d4859
Import changes
egregius313 Mar 17, 2023
f28f1af
Add `InsecureLdapUrlSink`
egregius313 Mar 17, 2023
0eaf222
Move public classes/predicates to top of library file
egregius313 Mar 17, 2023
43d79dc
Apply docs review suggestions
egregius313 Mar 24, 2023
106e5e7
Docs review suggestion
egregius313 Mar 24, 2023
9bfb13b
Update to the `Global`/`flow*` api
egregius313 Mar 27, 2023
97ec808
Make configuration public
egregius313 Mar 28, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Add InsecureLdapUrlSink
  • Loading branch information
egregius313 committed Mar 27, 2023
commit f28f1af5a4e0c856707220aa3d58a154cb322a74
10 changes: 10 additions & 0 deletions java/ql/lib/semmle/code/java/security/InsecureLdapAuth.qll
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
/** Provides classes to reason about insecure LDAP authentication. */

import java
private import semmle.code.java.dataflow.DataFlow
private import semmle.code.java.frameworks.Networking
private import semmle.code.java.frameworks.Jndi

Expand Down Expand Up @@ -113,3 +114,12 @@ predicate isSslEnv(MethodAccess ma) {
hasFieldValueEnv(ma, "java.naming.security.protocol", "ssl") or
hasFieldNameEnv(ma, "SECURITY_PROTOCOL", "ssl")
}

class InsecureLdapUrlSink extends DataFlow::Node {
InsecureLdapUrlSink() {
exists(ConstructorCall cc |
cc.getConstructedType().getAnAncestor() instanceof TypeDirContext and
this.asExpr() = cc.getArgument(0)
)
}
}
27 changes: 7 additions & 20 deletions java/ql/lib/semmle/code/java/security/InsecureLdapAuthQuery.qll
Original file line number Diff line number Diff line change
Expand Up @@ -12,12 +12,7 @@ import semmle.code.java.security.InsecureLdapAuth
private module InsecureLdapUrlConfig implements DataFlow::ConfigSig {
Comment thread
egregius313 marked this conversation as resolved.
Outdated
predicate isSource(DataFlow::Node src) { src.asExpr() instanceof InsecureLdapUrl }

predicate isSink(DataFlow::Node sink) {
exists(ConstructorCall cc |
cc.getConstructedType().getAnAncestor() instanceof TypeDirContext and
sink.asExpr() = cc.getArgument(0)
)
}
predicate isSink(DataFlow::Node sink) { sink instanceof InsecureLdapUrlSink }

/** Method call of `env.put()`. */
predicate isAdditionalFlowStep(DataFlow::Node pred, DataFlow::Node succ) {
Expand All @@ -37,16 +32,12 @@ module InsecureLdapUrlFlow = TaintTracking::Make<InsecureLdapUrlConfig>;
private module BasicAuthConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node src) {
Comment thread Fixed
exists(MethodAccess ma |
isBasicAuthEnv(ma) and ma.getQualifier() = src.(DataFlow::PostUpdateNode).getPreUpdateNode().asExpr()
isBasicAuthEnv(ma) and
ma.getQualifier() = src.(DataFlow::PostUpdateNode).getPreUpdateNode().asExpr()
)
}

predicate isSink(DataFlow::Node sink) {
exists(ConstructorCall cc |
cc.getConstructedType().getAnAncestor() instanceof TypeDirContext and
sink.asExpr() = cc.getArgument(0)
)
}
predicate isSink(DataFlow::Node sink) { sink instanceof InsecureLdapUrlSink }
}

module BasicAuthFlow = DataFlow::Make<BasicAuthConfig>;
Expand All @@ -57,16 +48,12 @@ module BasicAuthFlow = DataFlow::Make<BasicAuthConfig>;
private module RequiresSslConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node src) {
Comment thread Fixed
exists(MethodAccess ma |
isSslEnv(ma) and ma.getQualifier() = src.(DataFlow::PostUpdateNode).getPreUpdateNode().asExpr()
isSslEnv(ma) and
ma.getQualifier() = src.(DataFlow::PostUpdateNode).getPreUpdateNode().asExpr()
)
}

predicate isSink(DataFlow::Node sink) {
exists(ConstructorCall cc |
cc.getConstructedType().getAnAncestor() instanceof TypeDirContext and
sink.asExpr() = cc.getArgument(0)
)
}
predicate isSink(DataFlow::Node sink) { sink instanceof InsecureLdapUrlSink }
}

module RequiresSslFlow = DataFlow::Make<RequiresSslConfig>;