Skip to content

Commit 9a31ed1

Browse files
committed
add test case
1 parent dea2eb5 commit 9a31ed1

4 files changed

Lines changed: 115 additions & 0 deletions

File tree

Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
nodes
2+
| logInjectionBad.js:19:9:19:36 | q |
3+
| logInjectionBad.js:19:13:19:36 | url.par ... , true) |
4+
| logInjectionBad.js:19:23:19:29 | req.url |
5+
| logInjectionBad.js:19:23:19:29 | req.url |
6+
| logInjectionBad.js:20:9:20:35 | username |
7+
| logInjectionBad.js:20:20:20:20 | q |
8+
| logInjectionBad.js:20:20:20:26 | q.query |
9+
| logInjectionBad.js:20:20:20:35 | q.query.username |
10+
| logInjectionBad.js:22:18:22:43 | `[INFO] ... rname}` |
11+
| logInjectionBad.js:22:18:22:43 | `[INFO] ... rname}` |
12+
| logInjectionBad.js:22:34:22:41 | username |
13+
| logInjectionBad.js:23:37:23:44 | username |
14+
| logInjectionBad.js:23:37:23:44 | username |
15+
| logInjectionBad.js:24:35:24:42 | username |
16+
| logInjectionBad.js:24:35:24:42 | username |
17+
| logInjectionBad.js:25:36:25:43 | username |
18+
| logInjectionBad.js:25:36:25:43 | username |
19+
| logInjectionBad.js:28:9:28:32 | exceptional return of check_u ... ername) |
20+
| logInjectionBad.js:28:24:28:31 | username |
21+
| logInjectionBad.js:29:14:29:18 | error |
22+
| logInjectionBad.js:30:23:30:49 | `[ERROR ... rror}"` |
23+
| logInjectionBad.js:30:23:30:49 | `[ERROR ... rror}"` |
24+
| logInjectionBad.js:30:42:30:46 | error |
25+
edges
26+
| logInjectionBad.js:19:9:19:36 | q | logInjectionBad.js:20:20:20:20 | q |
27+
| logInjectionBad.js:19:13:19:36 | url.par ... , true) | logInjectionBad.js:19:9:19:36 | q |
28+
| logInjectionBad.js:19:23:19:29 | req.url | logInjectionBad.js:19:13:19:36 | url.par ... , true) |
29+
| logInjectionBad.js:19:23:19:29 | req.url | logInjectionBad.js:19:13:19:36 | url.par ... , true) |
30+
| logInjectionBad.js:20:9:20:35 | username | logInjectionBad.js:22:34:22:41 | username |
31+
| logInjectionBad.js:20:9:20:35 | username | logInjectionBad.js:23:37:23:44 | username |
32+
| logInjectionBad.js:20:9:20:35 | username | logInjectionBad.js:23:37:23:44 | username |
33+
| logInjectionBad.js:20:9:20:35 | username | logInjectionBad.js:24:35:24:42 | username |
34+
| logInjectionBad.js:20:9:20:35 | username | logInjectionBad.js:24:35:24:42 | username |
35+
| logInjectionBad.js:20:9:20:35 | username | logInjectionBad.js:25:36:25:43 | username |
36+
| logInjectionBad.js:20:9:20:35 | username | logInjectionBad.js:25:36:25:43 | username |
37+
| logInjectionBad.js:20:9:20:35 | username | logInjectionBad.js:28:24:28:31 | username |
38+
| logInjectionBad.js:20:20:20:20 | q | logInjectionBad.js:20:20:20:26 | q.query |
39+
| logInjectionBad.js:20:20:20:26 | q.query | logInjectionBad.js:20:20:20:35 | q.query.username |
40+
| logInjectionBad.js:20:20:20:35 | q.query.username | logInjectionBad.js:20:9:20:35 | username |
41+
| logInjectionBad.js:22:34:22:41 | username | logInjectionBad.js:22:18:22:43 | `[INFO] ... rname}` |
42+
| logInjectionBad.js:22:34:22:41 | username | logInjectionBad.js:22:18:22:43 | `[INFO] ... rname}` |
43+
| logInjectionBad.js:28:9:28:32 | exceptional return of check_u ... ername) | logInjectionBad.js:29:14:29:18 | error |
44+
| logInjectionBad.js:28:24:28:31 | username | logInjectionBad.js:28:9:28:32 | exceptional return of check_u ... ername) |
45+
| logInjectionBad.js:29:14:29:18 | error | logInjectionBad.js:30:42:30:46 | error |
46+
| logInjectionBad.js:30:42:30:46 | error | logInjectionBad.js:30:23:30:49 | `[ERROR ... rror}"` |
47+
| logInjectionBad.js:30:42:30:46 | error | logInjectionBad.js:30:23:30:49 | `[ERROR ... rror}"` |
48+
#select
49+
| logInjectionBad.js:22:18:22:43 | `[INFO] ... rname}` | logInjectionBad.js:19:23:19:29 | req.url | logInjectionBad.js:22:18:22:43 | `[INFO] ... rname}` | $@ flows to log entry. | logInjectionBad.js:19:23:19:29 | req.url | User-provided value |
50+
| logInjectionBad.js:23:37:23:44 | username | logInjectionBad.js:19:23:19:29 | req.url | logInjectionBad.js:23:37:23:44 | username | $@ flows to log entry. | logInjectionBad.js:19:23:19:29 | req.url | User-provided value |
51+
| logInjectionBad.js:24:35:24:42 | username | logInjectionBad.js:19:23:19:29 | req.url | logInjectionBad.js:24:35:24:42 | username | $@ flows to log entry. | logInjectionBad.js:19:23:19:29 | req.url | User-provided value |
52+
| logInjectionBad.js:25:36:25:43 | username | logInjectionBad.js:19:23:19:29 | req.url | logInjectionBad.js:25:36:25:43 | username | $@ flows to log entry. | logInjectionBad.js:19:23:19:29 | req.url | User-provided value |
53+
| logInjectionBad.js:30:23:30:49 | `[ERROR ... rror}"` | logInjectionBad.js:19:23:19:29 | req.url | logInjectionBad.js:30:23:30:49 | `[ERROR ... rror}"` | $@ flows to log entry. | logInjectionBad.js:19:23:19:29 | req.url | User-provided value |
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
Security/CWE-117/LogInjection.ql
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
const http = require('http');
2+
const hostname = '127.0.0.1';
3+
const port = 3000;
4+
const url = require('url');
5+
6+
7+
const check_username = (username) => {
8+
if (username != 'name') throw `${username} is not valid`;
9+
// do something
10+
}
11+
12+
const my_logger = {
13+
log: console.log
14+
}
15+
16+
const another_logger = console.log
17+
18+
const server = http.createServer((req, res) => {
19+
let q = url.parse(req.url, true);
20+
let username = q.query.username;
21+
22+
console.info(`[INFO] User: ${username}`); // NOT OK
23+
console.info(`[INFO] User: %s`, username); // NOT OK
24+
my_logger.log('[INFO] User:', username); // NOT OK
25+
another_logger('[INFO] User:', username); // NOT OK
26+
27+
try {
28+
check_username(username)
29+
} catch (error) {
30+
console.error(`[ERROR] Error: "${error}"`); // NOT OK
31+
}
32+
});
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
const http = require('http');
2+
const url = require('url');
3+
4+
const check_username = (username) => {
5+
if (username != 'name') throw `${username} is not valid`;
6+
}
7+
8+
const logger = {
9+
log: console.log
10+
}
11+
12+
const another_logger = console.log
13+
14+
const server = http.createServer((req, res) => {
15+
let q = url.parse(req.url, true);
16+
17+
// GOOD: remove `\n` line from user controlled input before logging
18+
let username = q.query.username.replace(/\n|\r/g, "");
19+
20+
console.info(`[INFO] User: ${username}`); // OK
21+
console.info(`[INFO] User: %s`, username); // OK
22+
logger.log('[INFO] User:', username); // OK
23+
another_logger('[INFO] User:', username); // OK
24+
try {
25+
check_username(username)
26+
} catch (error) {
27+
console.error(`[ERROR] Error: "${error}"`);
28+
}
29+
});

0 commit comments

Comments
 (0)