False negative: AndroidInsecureLocalAuthentication.ql
まだ誰も着手していません。
評価
調査の方向性
Security/CWE/CWE-287/AndroidInsecureLocalAuthentication.ql から始め、報告されている Java の例を再現し、パラメータの直接使用、代入、委譲、およびヘルパーを介した呼び出しを比較します。提供された各バリエーションについて、クエリが安全でない認証処理を一貫して報告し、偽陰性がないことが完了の条件です。
索引モデルが issue の本文から書いたものです。
説明
Version
codeql 2.23.9
When I detect the code like this using Security/CWE/CWE-287/AndroidInsecureLocalAuthentication.ql, the problem is reported normally:
package scensct.core.pos;
import android.hardware.fingerprint.FingerprintManager;
public class PosCase1 extends FingerprintManager.AuthenticationCallback {
@Override
public void onAuthenticationSucceeded(FingerprintManager.AuthenticationResult result) { // [REPORTED LINE]
// Parameter 'result' is declared but never accessed or referenced.
// No cryptographic operation or any use of 'result'.
System.out.println("Authentication succeeded.");
}
}
However, when I insert a temporary variable, AndroidInsecureLocalAuthentication.ql is unable to detect the problem:
package scensct.var.pos;
import android.hardware.fingerprint.FingerprintManager;
public class PosCase1_Var3 extends FingerprintManager.AuthenticationCallback {
@Override
public void onAuthenticationSucceeded(FingerprintManager.AuthenticationResult result) {
// Introduce a temporary variable that shadows but does not use result.
Object ignored = result;
// Still no cryptographic operation or actual usage.
System.out.println("Authentication succeeded.");
// The 'ignored' variable is never read.
}
}
AndroidInsecureLocalAuthentication.ql scanning the following code also fails to detect the issue:
package scensct.var.pos;
import android.hardware.biometrics.BiometricPrompt;
public class PosCase2_Var1 extends BiometricPrompt.AuthenticationCallback {
@Override
public void onAuthenticationSucceeded(BiometricPrompt.AuthenticationResult result) {
// Introduce a temporary variable that does not change the usage
BiometricPrompt.AuthenticationResult res = result;
super.onAuthenticationSucceeded(res);
}
}
package scensct.var.pos;
import android.hardware.biometrics.BiometricPrompt;
public class PosCase2_Var4 extends BiometricPrompt.AuthenticationCallback {
// Extract a private helper method that only passes the parameter
private void callSuper(BiometricPrompt.AuthenticationResult r) {
super.onAuthenticationSucceeded(r);
}
@Override
public void onAuthenticationSucceeded(BiometricPrompt.AuthenticationResult result) {
callSuper(result);
}
}
package scensct.var.pos;
import android.hardware.biometrics.BiometricPrompt;
public class PosCase2_Var5 extends BiometricPrompt.AuthenticationCallback {
@Override
public void onAuthenticationSucceeded(BiometricPrompt.AuthenticationResult result) {
// Add a redundant local variable and a no-op statement
BiometricPrompt.AuthenticationResult authResult = result;
int dummy = 0; // unrelated to result
super.onAuthenticationSucceeded(authResult);
}
}
- 主要言語
- CodeQL
- スター
- 10.1k
- フォーク
- 2.1k
- 平均マージ
- 2日 16時間
- マージ済み PR(30日)
- 143
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
github/codeql のほかの issue
-
agentic-workflows
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
false-positive javascript
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
-
C#: cs/simplifiable-boolean-expression false positive on Nullable<bool> compared with a literal オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
-
false-positive
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
似ている issue
-
enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
canonical/paas-charm#368 · コメント 1 件 ·
-
enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
palladius/rails8-app-on-gcp#142 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
StevenBlack/hosts#3256 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
corsairdev/corsair#1764 ·
-
oblt-aw/detector/security
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100