Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 314980c

Browse files
smowtonowen-mc
authored andcommitted
Model taint-propagating methods in the core JAX-WS library.
1 parent 9335e09 commit 314980c

2 files changed

Lines changed: 249 additions & 0 deletions

File tree

java/ql/src/semmle/code/java/dataflow/ExternalFlow.qll

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -81,6 +81,7 @@ private module Frameworks {
8181
private import semmle.code.java.frameworks.apache.Lang
8282
private import semmle.code.java.frameworks.guava.Guava
8383
private import semmle.code.java.frameworks.jackson.JacksonSerializability
84+
private import semmle.code.java.frameworks.JaxWS
8485
private import semmle.code.java.security.ResponseSplitting
8586
private import semmle.code.java.security.InformationLeak
8687
private import semmle.code.java.security.XSS

java/ql/src/semmle/code/java/frameworks/JaxWS.qll

Lines changed: 248 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
import java
2+
private import semmle.code.java.dataflow.ExternalFlow
23

34
/**
45
* A JAX WS endpoint is constructed by the container, and its methods
@@ -280,3 +281,250 @@ class JaxRSProducesAnnotation extends JaxRSAnnotation {
280281
class JaxRSConsumesAnnotation extends JaxRSAnnotation {
281282
JaxRSConsumesAnnotation() { getType().hasQualifiedName("javax.ws.rs", "Consumes") }
282283
}
284+
285+
/**
286+
* Model Response:
287+
*
288+
* - the returned ResponseBuilder gains taint from a tainted entity or existing Response
289+
*/
290+
private class ResponseModel extends SummaryModelCsv {
291+
override predicate row(string row) {
292+
row =
293+
[
294+
"javax.ws.rs.core;Response;false;accepted;;;Argument[0];ReturnValue;taint",
295+
"javax.ws.rs.core;Response;false;fromResponse;;;Argument[0];ReturnValue;taint",
296+
"javax.ws.rs.core;Response;false;ok;;;Argument[0];ReturnValue;taint"
297+
]
298+
}
299+
}
300+
301+
/**
302+
* Model ResponseBuilder:
303+
*
304+
* - becomes tainted by a tainted entity, but not by metadata, headers etc
305+
* - build() method returns taint
306+
* - almost all methods are fluent, and so preserve value
307+
*/
308+
private class ResponseBuilderModel extends SummaryModelCsv {
309+
override predicate row(string row) {
310+
row =
311+
[
312+
"javax.ws.rs.core;Response$ResponseBuilder;true;build;;;Argument[-1];ReturnValue;taint",
313+
"javax.ws.rs.core;Response$ResponseBuilder;true;entity;;;Argument[0];Argument[-1];taint",
314+
"javax.ws.rs.core;Response$ResponseBuilder;true;allow;;;Argument[-1];ReturnValue;value",
315+
"javax.ws.rs.core;Response$ResponseBuilder;true;cacheControl;;;Argument[-1];ReturnValue;value",
316+
"javax.ws.rs.core;Response$ResponseBuilder;true;clone;;;Argument[-1];ReturnValue;taint",
317+
"javax.ws.rs.core;Response$ResponseBuilder;true;contentLocation;;;Argument[-1];ReturnValue;value",
318+
"javax.ws.rs.core;Response$ResponseBuilder;true;cookie;;;Argument[-1];ReturnValue;value",
319+
"javax.ws.rs.core;Response$ResponseBuilder;true;encoding;;;Argument[-1];ReturnValue;value",
320+
"javax.ws.rs.core;Response$ResponseBuilder;true;entity;;;Argument[-1];ReturnValue;value",
321+
"javax.ws.rs.core;Response$ResponseBuilder;true;expires;;;Argument[-1];ReturnValue;value",
322+
"javax.ws.rs.core;Response$ResponseBuilder;true;header;;;Argument[-1];ReturnValue;value",
323+
"javax.ws.rs.core;Response$ResponseBuilder;true;language;;;Argument[-1];ReturnValue;value",
324+
"javax.ws.rs.core;Response$ResponseBuilder;true;lastModified;;;Argument[-1];ReturnValue;value",
325+
"javax.ws.rs.core;Response$ResponseBuilder;true;link;;;Argument[-1];ReturnValue;value",
326+
"javax.ws.rs.core;Response$ResponseBuilder;true;links;;;Argument[-1];ReturnValue;value",
327+
"javax.ws.rs.core;Response$ResponseBuilder;true;location;;;Argument[-1];ReturnValue;value",
328+
"javax.ws.rs.core;Response$ResponseBuilder;true;replaceAll;;;Argument[-1];ReturnValue;value",
329+
"javax.ws.rs.core;Response$ResponseBuilder;true;status;;;Argument[-1];ReturnValue;value",
330+
"javax.ws.rs.core;Response$ResponseBuilder;true;tag;;;Argument[-1];ReturnValue;value",
331+
"javax.ws.rs.core;Response$ResponseBuilder;true;type;;;Argument[-1];ReturnValue;value",
332+
"javax.ws.rs.core;Response$ResponseBuilder;true;variant;;;Argument[-1];ReturnValue;value",
333+
"javax.ws.rs.core;Response$ResponseBuilder;true;variants;;;Argument[-1];ReturnValue;value"
334+
]
335+
}
336+
}
337+
338+
/**
339+
* Model HttpHeaders: methods that Date have to be syntax-checked, but those returning MediaType
340+
* or Locale are assumed potentially dangerous, as these types do not generally check that the
341+
* input data is recognised, only that it conforms to the expected syntax.
342+
*/
343+
private class HttpHeadersModel extends SummaryModelCsv {
344+
override predicate row(string row) {
345+
row =
346+
[
347+
"javax.ws.rs.core;HttpHeaders;true;getAcceptableLanguages;;;Argument[-1];ReturnValue;taint",
348+
"javax.ws.rs.core;HttpHeaders;true;getAcceptableMediaTypes;;;Argument[-1];ReturnValue;taint",
349+
"javax.ws.rs.core;HttpHeaders;true;getCookies;;;Argument[-1];ReturnValue;taint",
350+
"javax.ws.rs.core;HttpHeaders;true;getHeaderString;;;Argument[-1];ReturnValue;taint",
351+
"javax.ws.rs.core;HttpHeaders;true;getLanguage;;;Argument[-1];ReturnValue;taint",
352+
"javax.ws.rs.core;HttpHeaders;true;getMediaType;;;Argument[-1];ReturnValue;taint",
353+
"javax.ws.rs.core;HttpHeaders;true;getRequestHeader;;;Argument[-1];ReturnValue;taint",
354+
"javax.ws.rs.core;HttpHeaders;true;getRequestHeaders;;;Argument[-1];ReturnValue;taint"
355+
]
356+
}
357+
}
358+
359+
/**
360+
* Model MultivaluedMap, which extends Map<List<K>, V> and provides a few extra helper methods.
361+
*/
362+
private class MultivaluedMapModel extends SummaryModelCsv {
363+
override predicate row(string row) {
364+
row =
365+
[
366+
"javax.ws.rs.core;MultivaluedMap;true;add;;;Argument;Argument[-1];taint",
367+
"javax.ws.rs.core;MultivaluedMap;true;addAll;;;Argument;Argument[-1];taint",
368+
"javax.ws.rs.core;MultivaluedMap;true;addFirst;;;Argument;Argument[-1];taint",
369+
"javax.ws.rs.core;MultivaluedMap;true;getFirst;;;Argument[-1];ReturnValue;taint",
370+
"javax.ws.rs.core;MultivaluedMap;true;putSingle;;;Argument;Argument[-1];taint"
371+
]
372+
}
373+
}
374+
375+
/**
376+
* Model PathSegment, which wraps a path and its associated matrix parameters.
377+
*/
378+
private class PathSegmentModel extends SummaryModelCsv {
379+
override predicate row(string row) {
380+
row =
381+
[
382+
"javax.ws.rs.core;PathSegment;true;getMatrixParameters;;;Argument[-1];ReturnValue;taint",
383+
"javax.ws.rs.core;PathSegment;true;getPath;;;Argument[-1];ReturnValue;taint"
384+
]
385+
}
386+
}
387+
388+
/**
389+
* Model UriInfo, which provides URI element accessors.
390+
*/
391+
private class UriInfoModel extends SummaryModelCsv {
392+
override predicate row(string row) {
393+
row =
394+
[
395+
"javax.ws.rs.core;UriInfo;true;getPathParameters;;;Argument[-1];ReturnValue;taint",
396+
"javax.ws.rs.core;UriInfo;true;getPathSegments;;;Argument[-1];ReturnValue;taint",
397+
"javax.ws.rs.core;UriInfo;true;getQueryParameters;;;Argument[-1];ReturnValue;taint",
398+
"javax.ws.rs.core;UriInfo;true;getRequestUri;;;Argument[-1];ReturnValue;taint",
399+
"javax.ws.rs.core;UriInfo;true;getRequestUriBuilder;;;Argument[-1];ReturnValue;taint"
400+
]
401+
}
402+
}
403+
404+
/**
405+
* Model Cookie, a simple tuple type.
406+
*/
407+
private class CookieModel extends SummaryModelCsv {
408+
override predicate row(string row) {
409+
row =
410+
[
411+
"javax.ws.rs.core;Cookie;true;getDomain;;;Argument[-1];ReturnValue;taint",
412+
"javax.ws.rs.core;Cookie;true;getName;;;Argument[-1];ReturnValue;taint",
413+
"javax.ws.rs.core;Cookie;true;getPath;;;Argument[-1];ReturnValue;taint",
414+
"javax.ws.rs.core;Cookie;true;getValue;;;Argument[-1];ReturnValue;taint",
415+
"javax.ws.rs.core;Cookie;true;getVersion;;;Argument[-1];ReturnValue;taint",
416+
"javax.ws.rs.core;Cookie;true;toString;;;Argument[-1];ReturnValue;taint",
417+
"javax.ws.rs.core;Cookie;false;Cookie;;;Argument;Argument[-1];taint",
418+
"javax.ws.rs.core;Cookie;false;valueOf;;;Argument;ReturnValue;taint"
419+
]
420+
}
421+
}
422+
423+
/**
424+
* Model Form, a simple container type.
425+
*/
426+
private class FormModel extends SummaryModelCsv {
427+
override predicate row(string row) {
428+
row =
429+
[
430+
"javax.ws.rs.core;Form;true;asMap;;;Argument[-1];ReturnValue;taint",
431+
"javax.ws.rs.core;Form;true;param;;;Argument;Argument[-1];taint",
432+
"javax.ws.rs.core;Form;true;param;;;Argument[-1];ReturnValue;value"
433+
]
434+
}
435+
}
436+
437+
/**
438+
* Model GenericEntity, a wrapper for HTTP entities (e.g., documents).
439+
*/
440+
private class GenericEntityModel extends SummaryModelCsv {
441+
override predicate row(string row) {
442+
row =
443+
[
444+
"javax.ws.rs.core;GenericEntity;false;GenericEntity;;;Argument[0];Argument[-1];taint",
445+
"javax.ws.rs.core;GenericEntity;true;getEntity;;;Argument[-1];ReturnValue;taint"
446+
]
447+
}
448+
}
449+
450+
/**
451+
* Model MediaType, which provides accessors for elements of Content-Type and similar
452+
* media type specifications.
453+
*/
454+
private class MediaTypeModel extends SummaryModelCsv {
455+
override predicate row(string row) {
456+
row =
457+
[
458+
"javax.ws.rs.core;MediaType;false;MediaType;;;Argument;Argument[-1];taint",
459+
"javax.ws.rs.core;MediaType;true;getParameters;;;Argument[-1];ReturnValue;taint",
460+
"javax.ws.rs.core;MediaType;true;getSubtype;;;Argument[-1];ReturnValue;taint",
461+
"javax.ws.rs.core;MediaType;true;getType;;;Argument[-1];ReturnValue;taint",
462+
"javax.ws.rs.core;MediaType;false;valueOf;;;Argument;ReturnValue;taint",
463+
"javax.ws.rs.core;MediaType;true;withCharset;;;Argument[-1];ReturnValue;taint"
464+
]
465+
}
466+
}
467+
468+
/**
469+
* Model UriBuilder, which provides a fluent interface to build a URI from components.
470+
*/
471+
private class UriBuilderModel extends SummaryModelCsv {
472+
override predicate row(string row) {
473+
row =
474+
[
475+
"javax.ws.rs.core;UriBuilder;true;build;;;Argument[0];ReturnValue;taint",
476+
"javax.ws.rs.core;UriBuilder;true;build;;;Argument[-1];ReturnValue;taint",
477+
"javax.ws.rs.core;UriBuilder;true;buildFromEncoded;;;Argument;ReturnValue;taint",
478+
"javax.ws.rs.core;UriBuilder;true;buildFromEncoded;;;Argument[-1];ReturnValue;taint",
479+
"javax.ws.rs.core;UriBuilder;true;buildFromEncodedMap;;;Argument;ReturnValue;taint",
480+
"javax.ws.rs.core;UriBuilder;true;buildFromEncodedMap;;;Argument[-1];ReturnValue;taint",
481+
"javax.ws.rs.core;UriBuilder;true;buildFromMap;;;Argument[0];ReturnValue;taint",
482+
"javax.ws.rs.core;UriBuilder;true;buildFromMap;;;Argument[-1];ReturnValue;taint",
483+
"javax.ws.rs.core;UriBuilder;true;clone;;;Argument[-1];ReturnValue;taint",
484+
"javax.ws.rs.core;UriBuilder;true;fragment;;;Argument;ReturnValue;taint",
485+
"javax.ws.rs.core;UriBuilder;true;fragment;;;Argument[-1];ReturnValue;value",
486+
"javax.ws.rs.core;UriBuilder;false;fromLink;;;Argument;ReturnValue;taint",
487+
"javax.ws.rs.core;UriBuilder;false;fromPath;;;Argument;ReturnValue;taint",
488+
"javax.ws.rs.core;UriBuilder;false;fromUri;;;Argument;ReturnValue;taint",
489+
"javax.ws.rs.core;UriBuilder;true;host;;;Argument;ReturnValue;taint",
490+
"javax.ws.rs.core;UriBuilder;true;host;;;Argument[-1];ReturnValue;value",
491+
"javax.ws.rs.core;UriBuilder;true;matrixParam;;;Argument;ReturnValue;taint",
492+
"javax.ws.rs.core;UriBuilder;true;matrixParam;;;Argument[-1];ReturnValue;value",
493+
"javax.ws.rs.core;UriBuilder;true;path;;;Argument;ReturnValue;taint",
494+
"javax.ws.rs.core;UriBuilder;true;path;;;Argument[-1];ReturnValue;value",
495+
"javax.ws.rs.core;UriBuilder;true;queryParam;;;Argument;ReturnValue;taint",
496+
"javax.ws.rs.core;UriBuilder;true;queryParam;;;Argument[-1];ReturnValue;value",
497+
"javax.ws.rs.core;UriBuilder;true;replaceMatrix;;;Argument;ReturnValue;taint",
498+
"javax.ws.rs.core;UriBuilder;true;replaceMatrix;;;Argument[-1];ReturnValue;value",
499+
"javax.ws.rs.core;UriBuilder;true;replaceMatrixParam;;;Argument;ReturnValue;taint",
500+
"javax.ws.rs.core;UriBuilder;true;replaceMatrixParam;;;Argument[-1];ReturnValue;value",
501+
"javax.ws.rs.core;UriBuilder;true;replacePath;;;Argument;ReturnValue;taint",
502+
"javax.ws.rs.core;UriBuilder;true;replacePath;;;Argument[-1];ReturnValue;value",
503+
"javax.ws.rs.core;UriBuilder;true;replaceQuery;;;Argument;ReturnValue;taint",
504+
"javax.ws.rs.core;UriBuilder;true;replaceQuery;;;Argument[-1];ReturnValue;value",
505+
"javax.ws.rs.core;UriBuilder;true;replaceQueryParam;;;Argument;ReturnValue;taint",
506+
"javax.ws.rs.core;UriBuilder;true;replaceQueryParam;;;Argument[-1];ReturnValue;value",
507+
"javax.ws.rs.core;UriBuilder;true;resolveTemplate;;;Argument;ReturnValue;taint",
508+
"javax.ws.rs.core;UriBuilder;true;resolveTemplate;;;Argument[-1];ReturnValue;value",
509+
"javax.ws.rs.core;UriBuilder;true;resolveTemplateFromEncoded;;;Argument;ReturnValue;taint",
510+
"javax.ws.rs.core;UriBuilder;true;resolveTemplateFromEncoded;;;Argument[-1];ReturnValue;value",
511+
"javax.ws.rs.core;UriBuilder;true;resolveTemplates;;;Argument;ReturnValue;taint",
512+
"javax.ws.rs.core;UriBuilder;true;resolveTemplates;;;Argument[-1];ReturnValue;value",
513+
"javax.ws.rs.core;UriBuilder;true;resolveTemplatesFromEncoded;;;Argument;ReturnValue;taint",
514+
"javax.ws.rs.core;UriBuilder;true;resolveTemplatesFromEncoded;;;Argument[-1];ReturnValue;value",
515+
"javax.ws.rs.core;UriBuilder;true;scheme;;;Argument;ReturnValue;taint",
516+
"javax.ws.rs.core;UriBuilder;true;scheme;;;Argument[-1];ReturnValue;value",
517+
"javax.ws.rs.core;UriBuilder;true;schemeSpecificPart;;;Argument;ReturnValue;taint",
518+
"javax.ws.rs.core;UriBuilder;true;schemeSpecificPart;;;Argument[-1];ReturnValue;value",
519+
"javax.ws.rs.core;UriBuilder;true;segment;;;Argument;ReturnValue;taint",
520+
"javax.ws.rs.core;UriBuilder;true;segment;;;Argument[-1];ReturnValue;value",
521+
"javax.ws.rs.core;UriBuilder;true;schemeSpecificPart;;;Argument;ReturnValue;taint",
522+
"javax.ws.rs.core;UriBuilder;true;schemeSpecificPart;;;Argument[-1];ReturnValue;value",
523+
"javax.ws.rs.core;UriBuilder;true;toTemplate;;;Argument[-1];ReturnValue;taint",
524+
"javax.ws.rs.core;UriBuilder;true;uri;;;Argument;ReturnValue;taint",
525+
"javax.ws.rs.core;UriBuilder;true;uri;;;Argument[-1];ReturnValue;value",
526+
"javax.ws.rs.core;UriBuilder;true;userInfo;;;Argument;ReturnValue;taint",
527+
"javax.ws.rs.core;UriBuilder;true;userInfo;;;Argument[-1];ReturnValue;value"
528+
]
529+
}
530+
}

0 commit comments

Comments
 (0)