mirror of
https://github.com/github/codeql.git
synced 2026-04-27 09:45:15 +02:00
Add webix copy function
This commit is contained in:
@@ -97,7 +97,7 @@ private class ExtendCallDeep extends ExtendCall {
|
||||
callee = LodashUnderscore::member("mergeWith") or
|
||||
callee = LodashUnderscore::member("defaultsDeep") or
|
||||
callee = AngularJS::angular().getAPropertyRead("merge") or
|
||||
callee = DataFlow::moduleImport("webix").getAPropertyRead("extend")
|
||||
callee = DataFlow::moduleImport("webix").getAPropertyRead(["extend", "copy"])
|
||||
)
|
||||
}
|
||||
|
||||
|
||||
@@ -173,7 +173,7 @@ module PrototypePollution {
|
||||
id = "angular"
|
||||
or
|
||||
call.isDeep() and
|
||||
call = DataFlow::moduleImport("webix").getAMemberCall("extend") and
|
||||
call = DataFlow::moduleImport("webix").getAMemberCall(["extend", "copy"]) and
|
||||
id = "webix"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -23,6 +23,10 @@ nodes
|
||||
| webix.js:4:22:4:43 | JSON.pa ... t.data) |
|
||||
| webix.js:4:33:4:37 | event |
|
||||
| webix.js:4:33:4:42 | event.data |
|
||||
| webix.js:5:19:5:40 | JSON.pa ... t.data) |
|
||||
| webix.js:5:19:5:40 | JSON.pa ... t.data) |
|
||||
| webix.js:5:30:5:34 | event |
|
||||
| webix.js:5:30:5:39 | event.data |
|
||||
edges
|
||||
| angularmerge.js:1:30:1:34 | event | angularmerge.js:2:32:2:36 | event |
|
||||
| angularmerge.js:1:30:1:34 | event | angularmerge.js:2:32:2:36 | event |
|
||||
@@ -40,12 +44,18 @@ edges
|
||||
| src-vulnerable-lodash/tst.js:18:16:18:25 | opts.thing | src-vulnerable-lodash/tst.js:17:17:19:5 | {\\n ... K\\n } |
|
||||
| webix.js:3:30:3:34 | event | webix.js:4:33:4:37 | event |
|
||||
| webix.js:3:30:3:34 | event | webix.js:4:33:4:37 | event |
|
||||
| webix.js:3:30:3:34 | event | webix.js:5:30:5:34 | event |
|
||||
| webix.js:3:30:3:34 | event | webix.js:5:30:5:34 | event |
|
||||
| webix.js:4:33:4:37 | event | webix.js:4:33:4:42 | event.data |
|
||||
| webix.js:4:33:4:42 | event.data | webix.js:4:22:4:43 | JSON.pa ... t.data) |
|
||||
| webix.js:4:33:4:42 | event.data | webix.js:4:22:4:43 | JSON.pa ... t.data) |
|
||||
| webix.js:5:30:5:34 | event | webix.js:5:30:5:39 | event.data |
|
||||
| webix.js:5:30:5:39 | event.data | webix.js:5:19:5:40 | JSON.pa ... t.data) |
|
||||
| webix.js:5:30:5:39 | event.data | webix.js:5:19:5:40 | JSON.pa ... t.data) |
|
||||
#select
|
||||
| angularmerge.js:2:21:2:42 | JSON.pa ... t.data) | angularmerge.js:1:30:1:34 | event | angularmerge.js:2:21:2:42 | JSON.pa ... t.data) | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | angularmerge.js:1:30:1:34 | event | user-controlled value | angularmerge.js:2:3:2:43 | angular ... .data)) | angular |
|
||||
| src-vulnerable-lodash/tst.js:7:17:7:29 | req.query.foo | src-vulnerable-lodash/tst.js:7:17:7:29 | req.query.foo | src-vulnerable-lodash/tst.js:7:17:7:29 | req.query.foo | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | src-vulnerable-lodash/tst.js:7:17:7:29 | req.query.foo | user-controlled value | src-vulnerable-lodash/package.json:3:19:3:26 | "4.17.4" | lodash |
|
||||
| src-vulnerable-lodash/tst.js:10:17:12:5 | {\\n ... K\\n } | src-vulnerable-lodash/tst.js:11:16:11:30 | req.query.value | src-vulnerable-lodash/tst.js:10:17:12:5 | {\\n ... K\\n } | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | src-vulnerable-lodash/tst.js:11:16:11:30 | req.query.value | user-controlled value | src-vulnerable-lodash/package.json:3:19:3:26 | "4.17.4" | lodash |
|
||||
| src-vulnerable-lodash/tst.js:17:17:19:5 | {\\n ... K\\n } | src-vulnerable-lodash/tst.js:15:14:15:28 | req.query.value | src-vulnerable-lodash/tst.js:17:17:19:5 | {\\n ... K\\n } | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | src-vulnerable-lodash/tst.js:15:14:15:28 | req.query.value | user-controlled value | src-vulnerable-lodash/package.json:3:19:3:26 | "4.17.4" | lodash |
|
||||
| webix.js:4:22:4:43 | JSON.pa ... t.data) | webix.js:3:30:3:34 | event | webix.js:4:22:4:43 | JSON.pa ... t.data) | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | webix.js:3:30:3:34 | event | user-controlled value | webix.js:4:5:4:44 | webix.e ... .data)) | webix |
|
||||
| webix.js:5:19:5:40 | JSON.pa ... t.data) | webix.js:3:30:3:34 | event | webix.js:5:19:5:40 | JSON.pa ... t.data) | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | webix.js:3:30:3:34 | event | user-controlled value | webix.js:5:5:5:41 | webix.c ... .data)) | webix |
|
||||
|
||||
@@ -2,4 +2,5 @@ import * as webix from "webix";
|
||||
|
||||
addEventListener("message", (event) => {
|
||||
webix.extend({}, JSON.parse(event.data)); // NOT OK
|
||||
webix.copy({},JSON.parse(event.data)); // NOT OK
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user