mirror of
https://github.com/github/codeql.git
synced 2026-05-05 05:35:13 +02:00
add jsonpickle and pexpect libs in case of unsafe decoding and secondary command execution, add proper test cases
This commit is contained in:
@@ -0,0 +1,2 @@
|
||||
testFailures
|
||||
failures
|
||||
@@ -0,0 +1,2 @@
|
||||
import python
|
||||
import experimental.meta.ConceptsTest
|
||||
15
python/ql/test/library-tests/frameworks/jsonpickle/Decode.py
Normal file
15
python/ql/test/library-tests/frameworks/jsonpickle/Decode.py
Normal file
@@ -0,0 +1,15 @@
|
||||
import os
|
||||
|
||||
import jsonpickle
|
||||
|
||||
|
||||
class Thing(object):
|
||||
def __reduce__(self):
|
||||
return os.system, ("curl 127.0.0.1:1234",)
|
||||
|
||||
|
||||
obj = Thing()
|
||||
|
||||
pickledObj = jsonpickle.encode(obj)
|
||||
objUnPickled = jsonpickle.decode(pickledObj, safe=True) # $ decodeInput=pickledObj decodeOutput=jsonpickle.decode(..) decodeFormat=pickle decodeMayExecuteInput
|
||||
print(objUnPickled.name)
|
||||
Reference in New Issue
Block a user