Add webix copy function

This commit is contained in:
Kevin Stubbings
2023-06-22 22:16:28 -07:00
parent 7e7e2aaac7
commit 3605269e13
4 changed files with 13 additions and 2 deletions

View File

@@ -97,7 +97,7 @@ private class ExtendCallDeep extends ExtendCall {
callee = LodashUnderscore::member("mergeWith") or
callee = LodashUnderscore::member("defaultsDeep") or
callee = AngularJS::angular().getAPropertyRead("merge") or
callee = DataFlow::moduleImport("webix").getAPropertyRead("extend")
callee = DataFlow::moduleImport("webix").getAPropertyRead(["extend", "copy"])
)
}

View File

@@ -173,7 +173,7 @@ module PrototypePollution {
id = "angular"
or
call.isDeep() and
call = DataFlow::moduleImport("webix").getAMemberCall("extend") and
call = DataFlow::moduleImport("webix").getAMemberCall(["extend", "copy"]) and
id = "webix"
}
}

View File

@@ -23,6 +23,10 @@ nodes
| webix.js:4:22:4:43 | JSON.pa ... t.data) |
| webix.js:4:33:4:37 | event |
| webix.js:4:33:4:42 | event.data |
| webix.js:5:19:5:40 | JSON.pa ... t.data) |
| webix.js:5:19:5:40 | JSON.pa ... t.data) |
| webix.js:5:30:5:34 | event |
| webix.js:5:30:5:39 | event.data |
edges
| angularmerge.js:1:30:1:34 | event | angularmerge.js:2:32:2:36 | event |
| angularmerge.js:1:30:1:34 | event | angularmerge.js:2:32:2:36 | event |
@@ -40,12 +44,18 @@ edges
| src-vulnerable-lodash/tst.js:18:16:18:25 | opts.thing | src-vulnerable-lodash/tst.js:17:17:19:5 | {\\n ... K\\n } |
| webix.js:3:30:3:34 | event | webix.js:4:33:4:37 | event |
| webix.js:3:30:3:34 | event | webix.js:4:33:4:37 | event |
| webix.js:3:30:3:34 | event | webix.js:5:30:5:34 | event |
| webix.js:3:30:3:34 | event | webix.js:5:30:5:34 | event |
| webix.js:4:33:4:37 | event | webix.js:4:33:4:42 | event.data |
| webix.js:4:33:4:42 | event.data | webix.js:4:22:4:43 | JSON.pa ... t.data) |
| webix.js:4:33:4:42 | event.data | webix.js:4:22:4:43 | JSON.pa ... t.data) |
| webix.js:5:30:5:34 | event | webix.js:5:30:5:39 | event.data |
| webix.js:5:30:5:39 | event.data | webix.js:5:19:5:40 | JSON.pa ... t.data) |
| webix.js:5:30:5:39 | event.data | webix.js:5:19:5:40 | JSON.pa ... t.data) |
#select
| angularmerge.js:2:21:2:42 | JSON.pa ... t.data) | angularmerge.js:1:30:1:34 | event | angularmerge.js:2:21:2:42 | JSON.pa ... t.data) | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | angularmerge.js:1:30:1:34 | event | user-controlled value | angularmerge.js:2:3:2:43 | angular ... .data)) | angular |
| src-vulnerable-lodash/tst.js:7:17:7:29 | req.query.foo | src-vulnerable-lodash/tst.js:7:17:7:29 | req.query.foo | src-vulnerable-lodash/tst.js:7:17:7:29 | req.query.foo | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | src-vulnerable-lodash/tst.js:7:17:7:29 | req.query.foo | user-controlled value | src-vulnerable-lodash/package.json:3:19:3:26 | "4.17.4" | lodash |
| src-vulnerable-lodash/tst.js:10:17:12:5 | {\\n ... K\\n } | src-vulnerable-lodash/tst.js:11:16:11:30 | req.query.value | src-vulnerable-lodash/tst.js:10:17:12:5 | {\\n ... K\\n } | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | src-vulnerable-lodash/tst.js:11:16:11:30 | req.query.value | user-controlled value | src-vulnerable-lodash/package.json:3:19:3:26 | "4.17.4" | lodash |
| src-vulnerable-lodash/tst.js:17:17:19:5 | {\\n ... K\\n } | src-vulnerable-lodash/tst.js:15:14:15:28 | req.query.value | src-vulnerable-lodash/tst.js:17:17:19:5 | {\\n ... K\\n } | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | src-vulnerable-lodash/tst.js:15:14:15:28 | req.query.value | user-controlled value | src-vulnerable-lodash/package.json:3:19:3:26 | "4.17.4" | lodash |
| webix.js:4:22:4:43 | JSON.pa ... t.data) | webix.js:3:30:3:34 | event | webix.js:4:22:4:43 | JSON.pa ... t.data) | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | webix.js:3:30:3:34 | event | user-controlled value | webix.js:4:5:4:44 | webix.e ... .data)) | webix |
| webix.js:5:19:5:40 | JSON.pa ... t.data) | webix.js:3:30:3:34 | event | webix.js:5:19:5:40 | JSON.pa ... t.data) | Prototype pollution caused by merging a $@ using a vulnerable version of $@. | webix.js:3:30:3:34 | event | user-controlled value | webix.js:5:5:5:41 | webix.c ... .data)) | webix |

View File

@@ -2,4 +2,5 @@ import * as webix from "webix";
addEventListener("message", (event) => {
webix.extend({}, JSON.parse(event.data)); // NOT OK
webix.copy({},JSON.parse(event.data)); // NOT OK
});