Skip to content

Framework adaptor only connects first tainted arg to following nodes #73

Description

@davidoc

In get_func_cfg_with_tainted_args the following taints the args of a framework function, and then links the first arg to the following nodes:

# Taint all the arguments
for arg in args:
tainted_node = TaintedNode(arg, arg,
None, [],
line_number=definition_lineno,
path=definition.path)
function_entry_node.connect(tainted_node)
# 1 and not 0 so that Entry Node remains first in the list
func_cfg.nodes.insert(1, tainted_node)
first_arg = func_cfg.nodes[len(args)]
first_arg.connect(first_node_after_args)

For a framework function where multiple args are user-controlled, this could miss issues related to second or subsequent args. For example, in Django, URL path elements may be passed to a View as args.

For example /xss1/<param>/ could route to:

def xss1(request, param):
    return render(request, 'templates/xss.html', {'param': param})

The suggested fix is to connect each tainted node to the following node in the for loop:

        ...
        func_cfg.nodes.insert(1, tainted_node)
        tainted_node.connect(first_node_after_args)

Activity

  1. KevinHock commented on Dec 12, 2017

    @KevinHock
    Collaborator

    Thanks for making this 👍 I'll fix it in my next PR.

  2. davidoc commented on Dec 12, 2017

    @davidoc
    ContributorAuthor

    Thanks, I have the change locally here. Would it be OK to include this in a PR with a few other changes related to Django support, or better to handle it separately?

  3. KevinHock commented on Dec 12, 2017

    @KevinHock
    Collaborator

    Sure thing, you can put it all in one PR, I'll review it sometime during Dec 23rd-29th. Thanks :D

  4. added a commit that references this issue on Dec 12, 2017
    efbdbd7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions