
A CodeQL workshop covering CVE-2021-21380
In this workshop we will use syntactical and semantic reasoning to find a SQL injection in the XWiki platform's rating component documented by CVE-2021-21380
Please complete this section before the workshop, if possible.
Install Visual Studio Code.
Install the CodeQL extension for Visual Studio Code.
You do not need to install the CodeQL CLI: the extension will handle this for you.
Clone this repository:
git clone https://github.com/advanced-security/codeql-workshop-cve-2021-21380.git
xwiki-platform-CVE-2021-21380.zip file in the Explorer view and select the command CodeQL: Set Current Database.Cmd/Ctrl+Shift+P), search for and run the command CodeQL: Install Pack Dependencies.github in the box to filter the list.cve-2021-21380-exercises, cve-2021-21380-exercises-tests, cve-2021-21380-solutions, and cve-2021-21380-solutions-tests.The workshop is split into several exercises introducing the QL language support for Java and ends with a final query to find the known SQL injection. In these exercises you will learn:
In this workshop we will look for known SQL injection vulnerabilities in the XWiki Platform's ratings API component. Such vulnerabilities can occur in applications when information that is controlled by an external user makes its way to application code that insecurely construct a SQL query and executes it.
The known SQL injection discussed in this workshop is reviewed in GHSA-79rg-7mv3-jrr5 in GitHub Advisory Database. To find the SQL injection, and possible variants, we are going to the following sub-problems:
In the first few exercises we will reason about syntactic information, using the Abstract Syntax Tree (AST), to identify:
Find all methods with the name getAverageRating and its declaring type in the program by completing the query exercise1.ql
java module provides a class Method to reason about methods in a program.Method provides the member predicates getName and hasName to reason about the name of a method.Method provides the member getDeclaringType to reason about the type that declares the method.A solution can be found in the query exercise1.ql
A solution to exercise 1 returns a list of methods. Some of which are defined in an interface called RatingsManager and some which are defined in the classes AbstractRatingsManager and RatingsScriptService.
From the information returned by the query and XWiki component documentation we can deduce that:
Role, and an implementation annotated with Component.ScriptService are made accessible to wiki pages through scripting.Find all the classes annotated with the annotation Component by completing the query exercise2.ql.
Note that the fully qualified name of the annotation's type is org.xwiki.component.annotation.Component.
this in the /characteristic predicate/.Class class provides a method getAnAnnotation to get associated annotations.Annotation class provides the getType member predicate to reason about its type.Type class provides the member predicates getName and hasName to reason about the name of a type.RefType class, representing classes and interfaces, provides the member predicates getQualifiedName and hasQualifiedName to reason about the fully qualified name of the reftype.A solution can be found in the query exercise2.ql
Find all the components that implement the ScriptService interface by completing the query excercise3.ql
Class type provides the member predicate getASuperType to reason about a class its super types, that is types it extends or implements.A solution can be found in the query exercise3.ql