FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
codeql/python/ql/src/Security/CWE-611/Xxe.ql at codeql-cli/v2.19.2 · github/codeql · GitHub
Uh oh!
There was an error while loading.
Please reload this page
.
github
/
codeql
Public
Notifications
You must be signed in to change notification settings
Fork
2.1k
Star
10k
Code
Issues
997
Pull requests
467
Discussions
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Discussions
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
codeql
/
python
/
ql
/
src
/
Security
/
CWE-611
/
Xxe.ql
Copy path
More file actions
More file actions
Latest commit
History
History
History
23 lines (21 loc) · 710 Bytes
Breadcrumbs
codeql
/
python
/
ql
/
src
/
Security
/
CWE-611
/
Xxe.ql
Copy path
File metadata and controls
23 lines (21 loc) · 710 Bytes
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
/**
* @name XML external entity expansion
* @description Parsing user input as an XML document with external
* entity expansion is vulnerable to XXE attacks.
* @kind path-problem
* @problem.severity error
* @security-severity 9.1
* @precision high
* @id py/xxe
* @tags security
* external/cwe/cwe-611
* external/cwe/cwe-827
*/
import
python
import
semmle.python.security.dataflow.XxeQuery
import
XxeFlow
::
PathGraph
from
XxeFlow
::
PathNode
source
,
XxeFlow
::
PathNode
sink
where
XxeFlow
::
flowPath
(
source
,
sink
)
select
sink
.
getNode
(
)
,
source
,
sink
,
"XML parsing depends on a $@ without guarding against external entity expansion."
,
source
.
getNode
(
)
,
"user-provided value"
Back
|
FazBrowse Home
|
New Git URL