False Negative: ImplicitPendingIntents.ql misses mutable implicit PendingIntents once they are stored, enriched, or sent through slightly noisier code paths.
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 48/100
- Tipo de issue
- Bug
- Clareza
- Razoavelmente clara
- Status de atividade
- Pouca atividade
- Stack de tecnologia
- java
- Domínio
- mobile-dev, security
Direção de pesquisa
Comece por Security/CWE/CWE-927/ImplicitPendingIntents.ql e pelos exemplos afetados PosCase1.java, PosCase2.java e PosCase3.java. Reproduza os falsos negativos e rastreie como as gravações de parcelable, o armazenamento de campos e as leituras de arrays afetam o fluxo da construção ao envio; o trabalho estará concluído quando esses PendingIntents implícitos mutáveis enviados a destinatários não especificados forem sinalizados.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
False Negative: ImplicitPendingIntents.ql misses mutable implicit PendingIntents once they are stored, enriched, or sent through slightly noisier code paths.
Version
codeql 2.24.3
Checker
- Checker id:
Security/CWE/CWE-927/ImplicitPendingIntents.ql - Checker description: This checker detects when an implicit Intent is created and then flows into a PendingIntent that is sent to an unspecified third party.
Description of the false negative
These cases still create an implicit Intent, wrap it in a mutable PendingIntent, and then send that PendingIntent to an unspecified recipient. The extra parcelable write, field store, or unrelated array read does not change the security outcome.
Affected test cases
PosCase1.java
The intent remains implicit when it is wrapped in the PendingIntent and sent onward. The extra statements do not make it safe.
// Implicit Intent with mutable PendingIntent sent to third party, including allowed implicit read of parcelable extra, should be flagged as unsafe.
package scensct.core.pos;
import android.app.PendingIntent;
import android.content.Context;
import android.content.Intent;
import android.os.Parcelable;
public class PosCase1 {
public void sendPendingIntentToThirdParty(Context context, Parcelable extraData) {
// Implicit Intent creation
Intent implicitIntent = new Intent("com.example.ACTION_TRIGGER");
// Allowed implicit read of parcelable extra (policy allows reading parcelable extras)
implicitIntent.putExtra("key", extraData);
// Create mutable PendingIntent from implicit Intent
PendingIntent pending = PendingIntent.getActivity(
context,
0,
implicitIntent,
PendingIntent.FLAG_MUTABLE
);
// Send to unspecified third party via PendingIntent.send()
try {
pending.send();
} catch (PendingIntent.CanceledException e) {
// Handle exception
}
}
}
PosCase2.java
This still creates a mutable implicit PendingIntent for an unspecified recipient. The issue is unchanged.
// Implicit Intent with mutable PendingIntent sent to third party, including implicit read of PendingIntent field, should be flagged as unsafe.
package scensct.core.pos;
import android.app.PendingIntent;
import android.content.Context;
import android.content.Intent;
public class PosCase2 {
static class Container {
PendingIntent pendingIntentField;
}
public void sendPendingIntentToThirdParty(Context context, Container container) {
// Implicit Intent creation
Intent implicitIntent = new Intent("com.example.ACTION_TRIGGER");
// Create mutable PendingIntent from implicit Intent
PendingIntent pending = PendingIntent.getActivity(
context,
0,
implicitIntent,
PendingIntent.FLAG_MUTABLE
);
// Implicit read of PendingIntent field (reading container.pendingIntentField)
container.pendingIntentField = pending;
// Send to unspecified third party via PendingIntent.send()
try {
container.pendingIntentField.send();
} catch (PendingIntent.CanceledException e) {
// Handle exception
}
}
}
PosCase3.java
The added statements are incidental. The important part is that the implicit intent still flows into a third-party PendingIntent.
// Implicit Intent with mutable PendingIntent sent to third party, including implicit read of Intent array, should be flagged as unsafe.
package scensct.core.pos;
import android.app.PendingIntent;
import android.content.Context;
import android.content.Intent;
public class PosCase3 {
public void sendPendingIntentToThirdParty(Context context, Intent[] intentArray, int index) {
// Implicit Intent creation
Intent implicitIntent = new Intent("com.example.ACTION_TRIGGER");
// Create mutable PendingIntent from implicit Intent
PendingIntent pending = PendingIntent.getActivity(
context,
0,
implicitIntent,
PendingIntent.FLAG_MUTABLE
);
// Implicit read of Intent array (accessing intentArray[index])
Intent retrievedIntent = intentArray[index];
// Send to unspecified third party via PendingIntent.send()
try {
pending.send();
} catch (PendingIntent.CanceledException e) {
// Handle exception
}
}
}
Cause analysis
The query appears too dependent on a direct, linear construction-to-send pattern. Once the PendingIntent is written to a field, accompanied by another benign read, or the Intent is slightly enriched before wrapping, the result disappears.
That is too brittle for Security/CWE/CWE-927/ImplicitPendingIntents.ql. Real Android code rarely keeps these flows in a single minimal statement sequence.
References
None known.
- Linguagem predominante
- CodeQL
- Estrelas
- 10.1k
- Forks
- 2.1k
- Merge médio
- 2d 16h
- PRs com merge (30d)
- 143
Guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de github/codeql
-
agentic-workflows
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
-
false-positive javascript
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
-
C#: cs/simplifiable-boolean-expression false positive on Nullable<bool> compared with a literal Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 82/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
-
false-positive
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
Todas as issues de github/codeql
Issues semelhantes
-
Bug Flutter User Feedbacks
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
getsentry/sentry-dart#4042 · 1 comentário ·
-
bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
status-im/status-app#22516 · 1 comentário ·
-
[New Rule] (Cash Raven) Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
LibChecker/LibChecker-Rules#1391 ·
-
add device message for 2.60+ Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
deltachat/deltachat-desktop#6775 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
ankidroid/Anki-Android#21999 ·