In get_func_cfg_with_tainted_args the following taints the args of a framework function, and then links the first arg to the following nodes:
|
# Taint all the arguments |
|
for arg in args: |
|
tainted_node = TaintedNode(arg, arg, |
|
None, [], |
|
line_number=definition_lineno, |
|
path=definition.path) |
|
function_entry_node.connect(tainted_node) |
|
# 1 and not 0 so that Entry Node remains first in the list |
|
func_cfg.nodes.insert(1, tainted_node) |
|
|
|
first_arg = func_cfg.nodes[len(args)] |
|
first_arg.connect(first_node_after_args) |
For a framework function where multiple args are user-controlled, this could miss issues related to second or subsequent args. For example, in Django, URL path elements may be passed to a View as args.
For example /xss1/<param>/ could route to:
def xss1(request, param):
return render(request, 'templates/xss.html', {'param': param})
The suggested fix is to connect each tainted node to the following node in the for loop:
...
func_cfg.nodes.insert(1, tainted_node)
tainted_node.connect(first_node_after_args)
In
get_func_cfg_with_tainted_argsthe following taints the args of a framework function, and then links the first arg to the following nodes:pyt/pyt/framework_adaptor.py
Lines 41 to 52 in a762e00
For a framework function where multiple args are user-controlled, this could miss issues related to second or subsequent args. For example, in Django, URL path elements may be passed to a View as args.
For example
/xss1/<param>/could route to:The suggested fix is to connect each tainted node to the following node in the for loop: