Skip to content
This repository was archived by the owner on Jan 5, 2023. It is now read-only.
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Use TaintTracking an TaintTracking2
  • Loading branch information
gagliardetto authored and smowton committed Apr 8, 2021
commit 5351a8eeb7143f75e3f1fda90cbd425418e4f833
16 changes: 8 additions & 8 deletions ql/src/experimental/CWE-79/HTMLTemplateEscapingPassthrough.ql
Original file line number Diff line number Diff line change
Expand Up @@ -18,9 +18,9 @@ import DataFlow::PathGraph
* and `conversionSink` gets populated with the node where the conversion happens.
*/
predicate flowsFromUntrustedToConversion(
DataFlow::PathNode untrusted, string targetType, DataFlow::PathNode conversionSink
DataFlow::PathNode untrusted, string targetType, DataFlow2::PathNode conversionSink
) {
exists(FlowConfFromUntrustedToPassthroughTypeConversion cfg, DataFlow::PathNode source |
exists(FlowConfFromUntrustedToPassthroughTypeConversion cfg, DataFlow2::PathNode source |
cfg.hasFlowPath(source, conversionSink) and
source.getNode() = untrusted.getNode() and
targetType = cfg.getDstTypeName()
Expand All @@ -41,7 +41,7 @@ class PassthroughTypeName extends string {
* this allows the injection of arbitrary content (html, css, js) into the generated
* output of the templates.
*/
class FlowConfFromUntrustedToPassthroughTypeConversion extends TaintTracking::Configuration {
class FlowConfFromUntrustedToPassthroughTypeConversion extends TaintTracking2::Configuration {
string dstTypeName;

FlowConfFromUntrustedToPassthroughTypeConversion() {
Expand All @@ -68,11 +68,11 @@ class FlowConfFromUntrustedToPassthroughTypeConversion extends TaintTracking::Co
* Holds if the provided `conversion` node flows into the provided `execSink`.
*/
predicate flowsFromConversionToExec(
DataFlow::PathNode conversion, string targetType, DataFlow::PathNode execSink
DataFlow2::PathNode conversion, string targetType, DataFlow::PathNode execSink
) {
exists(
FlowConfPassthroughTypeConversionToTemplateExecutionCall cfg, DataFlow::PathNode source,
DataFlow::PathNode execSinkLocal
FlowConfPassthroughTypeConversionToTemplateExecutionCall cfg, DataFlow2::PathNode source,
DataFlow2::PathNode execSinkLocal
|
cfg.hasFlowPath(source, execSinkLocal) and
source.getNode() = conversion.getNode() and
Expand All @@ -85,7 +85,7 @@ predicate flowsFromConversionToExec(
* A taint-tracking configuration for reasoning about when the result of a conversion
* to a PassthroughType flows to a template execution call.
*/
class FlowConfPassthroughTypeConversionToTemplateExecutionCall extends TaintTracking::Configuration {
class FlowConfPassthroughTypeConversionToTemplateExecutionCall extends TaintTracking2::Configuration {
string dstTypeName;

FlowConfPassthroughTypeConversionToTemplateExecutionCall() {
Expand Down Expand Up @@ -147,7 +147,7 @@ predicate flowsFromUntrustedToExec(DataFlow::PathNode untrusted, DataFlow::PathN

from
DataFlow::PathNode untrustedSource, DataFlow::PathNode templateExecCall, string targetTypeName,
DataFlow::PathNode conversion
DataFlow2::PathNode conversion
where
// A = untrusted remote flow source
// B = conversion to PassthroughType
Expand Down