| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -12,9 +12,11 @@ import semmle.python.dataflow.new.TaintTracking | |||
| 12 | 12 | import XxeCustomizations::Xxe | |
| 13 | 13 | ||
| 14 | 14 | /** | |
| 15 | + * DEPRECATED: Use `XxeFlow` module instead. | ||
| 16 | + * | ||
| 15 | 17 | * A taint-tracking configuration for detecting "XML External Entity (XXE)" vulnerabilities. | |
| 16 | 18 | */ | |
| 17 | - class Configuration extends TaintTracking::Configuration { | ||
| 19 | + deprecated class Configuration extends TaintTracking::Configuration { | ||
| 18 | 20 | Configuration() { this = "Xxe" } | |
| 19 | 21 | ||
| 20 | 22 | override predicate isSource(DataFlow::Node source) { source instanceof Source } | |
@@ -26,3 +28,14 @@ class Configuration extends TaintTracking::Configuration { | |||
| 26 | 28 | node instanceof Sanitizer | |
| 27 | 29 | } | |
| 28 | 30 | } | |
| 31 | + | ||
| 32 | + private module XxeConfig implements DataFlow::ConfigSig { | ||
| 33 | + predicate isSource(DataFlow::Node source) { source instanceof Source } | ||
| 34 | + | ||
| 35 | + predicate isSink(DataFlow::Node sink) { sink instanceof Sink } | ||
| 36 | + | ||
| 37 | + predicate isBarrier(DataFlow::Node node) { node instanceof Sanitizer } | ||
| 38 | + } | ||
| 39 | + | ||
| 40 | + /** Global taint-tracking for detecting "XML External Entity (XXE)" vulnerabilities. */ | ||
| 41 | + module XxeFlow = TaintTracking::Global<XxeConfig>; | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -14,10 +14,10 @@ | |||
| 14 | 14 | ||
| 15 | 15 | import python | |
| 16 | 16 | import semmle.python.security.dataflow.XxeQuery | |
| 17 | - import DataFlow::PathGraph | ||
| 17 | + import XxeFlow::PathGraph | ||
| 18 | 18 | ||
| 19 | - from Configuration cfg, DataFlow::PathNode source, DataFlow::PathNode sink | ||
| 20 | - where cfg.hasFlowPath(source, sink) | ||
| 19 | + from XxeFlow::PathNode source, XxeFlow::PathNode sink | ||
| 20 | + where XxeFlow::flowPath(source, sink) | ||
| 21 | 21 | select sink.getNode(), source, sink, | |
| 22 | 22 | "XML parsing depends on a $@ without guarding against external entity expansion.", | |
| 23 | 23 | source.getNode(), "user-provided value" | |
| Back | FazBrowse Home | New Git URL |
0 commit comments