|
1 | 1 | import java |
| 2 | +private import semmle.code.java.dataflow.ExternalFlow |
2 | 3 |
|
3 | 4 | /** |
4 | 5 | * A JAX WS endpoint is constructed by the container, and its methods |
@@ -280,3 +281,250 @@ class JaxRSProducesAnnotation extends JaxRSAnnotation { |
280 | 281 | class JaxRSConsumesAnnotation extends JaxRSAnnotation { |
281 | 282 | JaxRSConsumesAnnotation() { getType().hasQualifiedName("javax.ws.rs", "Consumes") } |
282 | 283 | } |
| 284 | + |
| 285 | +/** |
| 286 | + * Model Response: |
| 287 | + * |
| 288 | + * - the returned ResponseBuilder gains taint from a tainted entity or existing Response |
| 289 | + */ |
| 290 | +private class ResponseModel extends SummaryModelCsv { |
| 291 | + override predicate row(string row) { |
| 292 | + row = |
| 293 | + [ |
| 294 | + "javax.ws.rs.core;Response;false;accepted;;;Argument[0];ReturnValue;taint", |
| 295 | + "javax.ws.rs.core;Response;false;fromResponse;;;Argument[0];ReturnValue;taint", |
| 296 | + "javax.ws.rs.core;Response;false;ok;;;Argument[0];ReturnValue;taint" |
| 297 | + ] |
| 298 | + } |
| 299 | +} |
| 300 | + |
| 301 | +/** |
| 302 | + * Model ResponseBuilder: |
| 303 | + * |
| 304 | + * - becomes tainted by a tainted entity, but not by metadata, headers etc |
| 305 | + * - build() method returns taint |
| 306 | + * - almost all methods are fluent, and so preserve value |
| 307 | + */ |
| 308 | +private class ResponseBuilderModel extends SummaryModelCsv { |
| 309 | + override predicate row(string row) { |
| 310 | + row = |
| 311 | + [ |
| 312 | + "javax.ws.rs.core;Response$ResponseBuilder;true;build;;;Argument[-1];ReturnValue;taint", |
| 313 | + "javax.ws.rs.core;Response$ResponseBuilder;true;entity;;;Argument[0];Argument[-1];taint", |
| 314 | + "javax.ws.rs.core;Response$ResponseBuilder;true;allow;;;Argument[-1];ReturnValue;value", |
| 315 | + "javax.ws.rs.core;Response$ResponseBuilder;true;cacheControl;;;Argument[-1];ReturnValue;value", |
| 316 | + "javax.ws.rs.core;Response$ResponseBuilder;true;clone;;;Argument[-1];ReturnValue;taint", |
| 317 | + "javax.ws.rs.core;Response$ResponseBuilder;true;contentLocation;;;Argument[-1];ReturnValue;value", |
| 318 | + "javax.ws.rs.core;Response$ResponseBuilder;true;cookie;;;Argument[-1];ReturnValue;value", |
| 319 | + "javax.ws.rs.core;Response$ResponseBuilder;true;encoding;;;Argument[-1];ReturnValue;value", |
| 320 | + "javax.ws.rs.core;Response$ResponseBuilder;true;entity;;;Argument[-1];ReturnValue;value", |
| 321 | + "javax.ws.rs.core;Response$ResponseBuilder;true;expires;;;Argument[-1];ReturnValue;value", |
| 322 | + "javax.ws.rs.core;Response$ResponseBuilder;true;header;;;Argument[-1];ReturnValue;value", |
| 323 | + "javax.ws.rs.core;Response$ResponseBuilder;true;language;;;Argument[-1];ReturnValue;value", |
| 324 | + "javax.ws.rs.core;Response$ResponseBuilder;true;lastModified;;;Argument[-1];ReturnValue;value", |
| 325 | + "javax.ws.rs.core;Response$ResponseBuilder;true;link;;;Argument[-1];ReturnValue;value", |
| 326 | + "javax.ws.rs.core;Response$ResponseBuilder;true;links;;;Argument[-1];ReturnValue;value", |
| 327 | + "javax.ws.rs.core;Response$ResponseBuilder;true;location;;;Argument[-1];ReturnValue;value", |
| 328 | + "javax.ws.rs.core;Response$ResponseBuilder;true;replaceAll;;;Argument[-1];ReturnValue;value", |
| 329 | + "javax.ws.rs.core;Response$ResponseBuilder;true;status;;;Argument[-1];ReturnValue;value", |
| 330 | + "javax.ws.rs.core;Response$ResponseBuilder;true;tag;;;Argument[-1];ReturnValue;value", |
| 331 | + "javax.ws.rs.core;Response$ResponseBuilder;true;type;;;Argument[-1];ReturnValue;value", |
| 332 | + "javax.ws.rs.core;Response$ResponseBuilder;true;variant;;;Argument[-1];ReturnValue;value", |
| 333 | + "javax.ws.rs.core;Response$ResponseBuilder;true;variants;;;Argument[-1];ReturnValue;value" |
| 334 | + ] |
| 335 | + } |
| 336 | +} |
| 337 | + |
| 338 | +/** |
| 339 | + * Model HttpHeaders: methods that Date have to be syntax-checked, but those returning MediaType |
| 340 | + * or Locale are assumed potentially dangerous, as these types do not generally check that the |
| 341 | + * input data is recognised, only that it conforms to the expected syntax. |
| 342 | + */ |
| 343 | +private class HttpHeadersModel extends SummaryModelCsv { |
| 344 | + override predicate row(string row) { |
| 345 | + row = |
| 346 | + [ |
| 347 | + "javax.ws.rs.core;HttpHeaders;true;getAcceptableLanguages;;;Argument[-1];ReturnValue;taint", |
| 348 | + "javax.ws.rs.core;HttpHeaders;true;getAcceptableMediaTypes;;;Argument[-1];ReturnValue;taint", |
| 349 | + "javax.ws.rs.core;HttpHeaders;true;getCookies;;;Argument[-1];ReturnValue;taint", |
| 350 | + "javax.ws.rs.core;HttpHeaders;true;getHeaderString;;;Argument[-1];ReturnValue;taint", |
| 351 | + "javax.ws.rs.core;HttpHeaders;true;getLanguage;;;Argument[-1];ReturnValue;taint", |
| 352 | + "javax.ws.rs.core;HttpHeaders;true;getMediaType;;;Argument[-1];ReturnValue;taint", |
| 353 | + "javax.ws.rs.core;HttpHeaders;true;getRequestHeader;;;Argument[-1];ReturnValue;taint", |
| 354 | + "javax.ws.rs.core;HttpHeaders;true;getRequestHeaders;;;Argument[-1];ReturnValue;taint" |
| 355 | + ] |
| 356 | + } |
| 357 | +} |
| 358 | + |
| 359 | +/** |
| 360 | + * Model MultivaluedMap, which extends Map<List<K>, V> and provides a few extra helper methods. |
| 361 | + */ |
| 362 | +private class MultivaluedMapModel extends SummaryModelCsv { |
| 363 | + override predicate row(string row) { |
| 364 | + row = |
| 365 | + [ |
| 366 | + "javax.ws.rs.core;MultivaluedMap;true;add;;;Argument;Argument[-1];taint", |
| 367 | + "javax.ws.rs.core;MultivaluedMap;true;addAll;;;Argument;Argument[-1];taint", |
| 368 | + "javax.ws.rs.core;MultivaluedMap;true;addFirst;;;Argument;Argument[-1];taint", |
| 369 | + "javax.ws.rs.core;MultivaluedMap;true;getFirst;;;Argument[-1];ReturnValue;taint", |
| 370 | + "javax.ws.rs.core;MultivaluedMap;true;putSingle;;;Argument;Argument[-1];taint" |
| 371 | + ] |
| 372 | + } |
| 373 | +} |
| 374 | + |
| 375 | +/** |
| 376 | + * Model PathSegment, which wraps a path and its associated matrix parameters. |
| 377 | + */ |
| 378 | +private class PathSegmentModel extends SummaryModelCsv { |
| 379 | + override predicate row(string row) { |
| 380 | + row = |
| 381 | + [ |
| 382 | + "javax.ws.rs.core;PathSegment;true;getMatrixParameters;;;Argument[-1];ReturnValue;taint", |
| 383 | + "javax.ws.rs.core;PathSegment;true;getPath;;;Argument[-1];ReturnValue;taint" |
| 384 | + ] |
| 385 | + } |
| 386 | +} |
| 387 | + |
| 388 | +/** |
| 389 | + * Model UriInfo, which provides URI element accessors. |
| 390 | + */ |
| 391 | +private class UriInfoModel extends SummaryModelCsv { |
| 392 | + override predicate row(string row) { |
| 393 | + row = |
| 394 | + [ |
| 395 | + "javax.ws.rs.core;UriInfo;true;getPathParameters;;;Argument[-1];ReturnValue;taint", |
| 396 | + "javax.ws.rs.core;UriInfo;true;getPathSegments;;;Argument[-1];ReturnValue;taint", |
| 397 | + "javax.ws.rs.core;UriInfo;true;getQueryParameters;;;Argument[-1];ReturnValue;taint", |
| 398 | + "javax.ws.rs.core;UriInfo;true;getRequestUri;;;Argument[-1];ReturnValue;taint", |
| 399 | + "javax.ws.rs.core;UriInfo;true;getRequestUriBuilder;;;Argument[-1];ReturnValue;taint" |
| 400 | + ] |
| 401 | + } |
| 402 | +} |
| 403 | + |
| 404 | +/** |
| 405 | + * Model Cookie, a simple tuple type. |
| 406 | + */ |
| 407 | +private class CookieModel extends SummaryModelCsv { |
| 408 | + override predicate row(string row) { |
| 409 | + row = |
| 410 | + [ |
| 411 | + "javax.ws.rs.core;Cookie;true;getDomain;;;Argument[-1];ReturnValue;taint", |
| 412 | + "javax.ws.rs.core;Cookie;true;getName;;;Argument[-1];ReturnValue;taint", |
| 413 | + "javax.ws.rs.core;Cookie;true;getPath;;;Argument[-1];ReturnValue;taint", |
| 414 | + "javax.ws.rs.core;Cookie;true;getValue;;;Argument[-1];ReturnValue;taint", |
| 415 | + "javax.ws.rs.core;Cookie;true;getVersion;;;Argument[-1];ReturnValue;taint", |
| 416 | + "javax.ws.rs.core;Cookie;true;toString;;;Argument[-1];ReturnValue;taint", |
| 417 | + "javax.ws.rs.core;Cookie;false;Cookie;;;Argument;Argument[-1];taint", |
| 418 | + "javax.ws.rs.core;Cookie;false;valueOf;;;Argument;ReturnValue;taint" |
| 419 | + ] |
| 420 | + } |
| 421 | +} |
| 422 | + |
| 423 | +/** |
| 424 | + * Model Form, a simple container type. |
| 425 | + */ |
| 426 | +private class FormModel extends SummaryModelCsv { |
| 427 | + override predicate row(string row) { |
| 428 | + row = |
| 429 | + [ |
| 430 | + "javax.ws.rs.core;Form;true;asMap;;;Argument[-1];ReturnValue;taint", |
| 431 | + "javax.ws.rs.core;Form;true;param;;;Argument;Argument[-1];taint", |
| 432 | + "javax.ws.rs.core;Form;true;param;;;Argument[-1];ReturnValue;value" |
| 433 | + ] |
| 434 | + } |
| 435 | +} |
| 436 | + |
| 437 | +/** |
| 438 | + * Model GenericEntity, a wrapper for HTTP entities (e.g., documents). |
| 439 | + */ |
| 440 | +private class GenericEntityModel extends SummaryModelCsv { |
| 441 | + override predicate row(string row) { |
| 442 | + row = |
| 443 | + [ |
| 444 | + "javax.ws.rs.core;GenericEntity;false;GenericEntity;;;Argument[0];Argument[-1];taint", |
| 445 | + "javax.ws.rs.core;GenericEntity;true;getEntity;;;Argument[-1];ReturnValue;taint" |
| 446 | + ] |
| 447 | + } |
| 448 | +} |
| 449 | + |
| 450 | +/** |
| 451 | + * Model MediaType, which provides accessors for elements of Content-Type and similar |
| 452 | + * media type specifications. |
| 453 | + */ |
| 454 | +private class MediaTypeModel extends SummaryModelCsv { |
| 455 | + override predicate row(string row) { |
| 456 | + row = |
| 457 | + [ |
| 458 | + "javax.ws.rs.core;MediaType;false;MediaType;;;Argument;Argument[-1];taint", |
| 459 | + "javax.ws.rs.core;MediaType;true;getParameters;;;Argument[-1];ReturnValue;taint", |
| 460 | + "javax.ws.rs.core;MediaType;true;getSubtype;;;Argument[-1];ReturnValue;taint", |
| 461 | + "javax.ws.rs.core;MediaType;true;getType;;;Argument[-1];ReturnValue;taint", |
| 462 | + "javax.ws.rs.core;MediaType;false;valueOf;;;Argument;ReturnValue;taint", |
| 463 | + "javax.ws.rs.core;MediaType;true;withCharset;;;Argument[-1];ReturnValue;taint" |
| 464 | + ] |
| 465 | + } |
| 466 | +} |
| 467 | + |
| 468 | +/** |
| 469 | + * Model UriBuilder, which provides a fluent interface to build a URI from components. |
| 470 | + */ |
| 471 | +private class UriBuilderModel extends SummaryModelCsv { |
| 472 | + override predicate row(string row) { |
| 473 | + row = |
| 474 | + [ |
| 475 | + "javax.ws.rs.core;UriBuilder;true;build;;;Argument[0];ReturnValue;taint", |
| 476 | + "javax.ws.rs.core;UriBuilder;true;build;;;Argument[-1];ReturnValue;taint", |
| 477 | + "javax.ws.rs.core;UriBuilder;true;buildFromEncoded;;;Argument;ReturnValue;taint", |
| 478 | + "javax.ws.rs.core;UriBuilder;true;buildFromEncoded;;;Argument[-1];ReturnValue;taint", |
| 479 | + "javax.ws.rs.core;UriBuilder;true;buildFromEncodedMap;;;Argument;ReturnValue;taint", |
| 480 | + "javax.ws.rs.core;UriBuilder;true;buildFromEncodedMap;;;Argument[-1];ReturnValue;taint", |
| 481 | + "javax.ws.rs.core;UriBuilder;true;buildFromMap;;;Argument[0];ReturnValue;taint", |
| 482 | + "javax.ws.rs.core;UriBuilder;true;buildFromMap;;;Argument[-1];ReturnValue;taint", |
| 483 | + "javax.ws.rs.core;UriBuilder;true;clone;;;Argument[-1];ReturnValue;taint", |
| 484 | + "javax.ws.rs.core;UriBuilder;true;fragment;;;Argument;ReturnValue;taint", |
| 485 | + "javax.ws.rs.core;UriBuilder;true;fragment;;;Argument[-1];ReturnValue;value", |
| 486 | + "javax.ws.rs.core;UriBuilder;false;fromLink;;;Argument;ReturnValue;taint", |
| 487 | + "javax.ws.rs.core;UriBuilder;false;fromPath;;;Argument;ReturnValue;taint", |
| 488 | + "javax.ws.rs.core;UriBuilder;false;fromUri;;;Argument;ReturnValue;taint", |
| 489 | + "javax.ws.rs.core;UriBuilder;true;host;;;Argument;ReturnValue;taint", |
| 490 | + "javax.ws.rs.core;UriBuilder;true;host;;;Argument[-1];ReturnValue;value", |
| 491 | + "javax.ws.rs.core;UriBuilder;true;matrixParam;;;Argument;ReturnValue;taint", |
| 492 | + "javax.ws.rs.core;UriBuilder;true;matrixParam;;;Argument[-1];ReturnValue;value", |
| 493 | + "javax.ws.rs.core;UriBuilder;true;path;;;Argument;ReturnValue;taint", |
| 494 | + "javax.ws.rs.core;UriBuilder;true;path;;;Argument[-1];ReturnValue;value", |
| 495 | + "javax.ws.rs.core;UriBuilder;true;queryParam;;;Argument;ReturnValue;taint", |
| 496 | + "javax.ws.rs.core;UriBuilder;true;queryParam;;;Argument[-1];ReturnValue;value", |
| 497 | + "javax.ws.rs.core;UriBuilder;true;replaceMatrix;;;Argument;ReturnValue;taint", |
| 498 | + "javax.ws.rs.core;UriBuilder;true;replaceMatrix;;;Argument[-1];ReturnValue;value", |
| 499 | + "javax.ws.rs.core;UriBuilder;true;replaceMatrixParam;;;Argument;ReturnValue;taint", |
| 500 | + "javax.ws.rs.core;UriBuilder;true;replaceMatrixParam;;;Argument[-1];ReturnValue;value", |
| 501 | + "javax.ws.rs.core;UriBuilder;true;replacePath;;;Argument;ReturnValue;taint", |
| 502 | + "javax.ws.rs.core;UriBuilder;true;replacePath;;;Argument[-1];ReturnValue;value", |
| 503 | + "javax.ws.rs.core;UriBuilder;true;replaceQuery;;;Argument;ReturnValue;taint", |
| 504 | + "javax.ws.rs.core;UriBuilder;true;replaceQuery;;;Argument[-1];ReturnValue;value", |
| 505 | + "javax.ws.rs.core;UriBuilder;true;replaceQueryParam;;;Argument;ReturnValue;taint", |
| 506 | + "javax.ws.rs.core;UriBuilder;true;replaceQueryParam;;;Argument[-1];ReturnValue;value", |
| 507 | + "javax.ws.rs.core;UriBuilder;true;resolveTemplate;;;Argument;ReturnValue;taint", |
| 508 | + "javax.ws.rs.core;UriBuilder;true;resolveTemplate;;;Argument[-1];ReturnValue;value", |
| 509 | + "javax.ws.rs.core;UriBuilder;true;resolveTemplateFromEncoded;;;Argument;ReturnValue;taint", |
| 510 | + "javax.ws.rs.core;UriBuilder;true;resolveTemplateFromEncoded;;;Argument[-1];ReturnValue;value", |
| 511 | + "javax.ws.rs.core;UriBuilder;true;resolveTemplates;;;Argument;ReturnValue;taint", |
| 512 | + "javax.ws.rs.core;UriBuilder;true;resolveTemplates;;;Argument[-1];ReturnValue;value", |
| 513 | + "javax.ws.rs.core;UriBuilder;true;resolveTemplatesFromEncoded;;;Argument;ReturnValue;taint", |
| 514 | + "javax.ws.rs.core;UriBuilder;true;resolveTemplatesFromEncoded;;;Argument[-1];ReturnValue;value", |
| 515 | + "javax.ws.rs.core;UriBuilder;true;scheme;;;Argument;ReturnValue;taint", |
| 516 | + "javax.ws.rs.core;UriBuilder;true;scheme;;;Argument[-1];ReturnValue;value", |
| 517 | + "javax.ws.rs.core;UriBuilder;true;schemeSpecificPart;;;Argument;ReturnValue;taint", |
| 518 | + "javax.ws.rs.core;UriBuilder;true;schemeSpecificPart;;;Argument[-1];ReturnValue;value", |
| 519 | + "javax.ws.rs.core;UriBuilder;true;segment;;;Argument;ReturnValue;taint", |
| 520 | + "javax.ws.rs.core;UriBuilder;true;segment;;;Argument[-1];ReturnValue;value", |
| 521 | + "javax.ws.rs.core;UriBuilder;true;schemeSpecificPart;;;Argument;ReturnValue;taint", |
| 522 | + "javax.ws.rs.core;UriBuilder;true;schemeSpecificPart;;;Argument[-1];ReturnValue;value", |
| 523 | + "javax.ws.rs.core;UriBuilder;true;toTemplate;;;Argument[-1];ReturnValue;taint", |
| 524 | + "javax.ws.rs.core;UriBuilder;true;uri;;;Argument;ReturnValue;taint", |
| 525 | + "javax.ws.rs.core;UriBuilder;true;uri;;;Argument[-1];ReturnValue;value", |
| 526 | + "javax.ws.rs.core;UriBuilder;true;userInfo;;;Argument;ReturnValue;taint", |
| 527 | + "javax.ws.rs.core;UriBuilder;true;userInfo;;;Argument[-1];ReturnValue;value" |
| 528 | + ] |
| 529 | + } |
| 530 | +} |
0 commit comments