JS: Add meta query for reporting threat model sources

This commit is contained in:
Asger F
2025-01-09 11:23:27 +01:00
parent 30d192a1db
commit 01f7d45e2d
3 changed files with 25 additions and 6 deletions

View File

@@ -11,6 +11,6 @@
import javascript
import meta.internal.TaintMetrics
from DataFlow::Node node
where node = relevantTaintSource()
from ThreatModelSource node
where node = relevantTaintSource() and node.getThreatModel() = "remote"
select node, getTaintSourceName(node)

View File

@@ -0,0 +1,19 @@
/**
* @name Threat model sources
* @description Sources of possibly untrusted input that can be configured via threat models.
* @kind problem
* @problem.severity recommendation
* @id js/meta/alerts/threat-model-sources
* @tags meta
* @precision very-low
*/
import javascript
import meta.internal.TaintMetrics
from ThreatModelSource node, string threatModel
where
node = relevantTaintSource() and
threatModel = node.getThreatModel() and
threatModel != "remote" // "remote" is reported by TaintSources.ql
select node, getTaintSourceName(node) + " (\"" + threatModel + "\" threat model)"