Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
codeql-workshop-cve-2021-21380 — A CodeQL workshop covering CVE-2021-21380 | Kitploit
Tools/GitHubGitHub/rvermeulen/codeql-workshop-cve-2021-21380
Static AnalysisVulnerability AnalysisCode AnalysisWeb SecurityLearning & EducationLabs & Practice
GitHubrvermeulen/codeql-workshop-cve-2021-21380

codeql-workshop-cve-2021-21380

A CodeQL workshop covering CVE-2021-21380

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
125141 year agoNot yet reviewed
Share

CodeQL workshop for Java: Finding a SQL injection

In this workshop we will use syntactical and semantic reasoning to find a SQL injection in the XWiki platform's rating component documented by CVE-2021-21380

Contents

  • CodeQL workshop for Java: Finding a SQL injection
    • Contents
    • Prerequisites and setup instructions
      • On your local machine
        • Installation
        • Setup steps
    • Workshop
      • Learnings
      • Problem statement
      • Exercises
        • Exercise 1
        • Intermezzo 1
        • Exercise 2
        • Exercise 3
        • Intermezzo 2
        • Exercise 4
        • Exercise 5
        • Intermezzo 3
        • Exercise 6
        • Exercise 7
        • Exercise 8
    • What's next?

Prerequisites and setup instructions

On your local machine

Please complete this section before the workshop, if possible.

Installation

  • Install Visual Studio Code.

  • Install the CodeQL extension for Visual Studio Code.

  • You do not need to install the CodeQL CLI: the extension will handle this for you.

  • Clone this repository:

    git clone https://github.com/advanced-security/codeql-workshop-cve-2021-21380.git
    

Setup steps

  • Import the CodeQL database to be used in the workshop:
    • Right-click on the xwiki-platform-CVE-2021-21380.zip file in the Explorer view and select the command CodeQL: Set Current Database.
    • The database will show up in the CodeQL databases view reachable from the QL icon on the Activity Bar.
  • Install the dependencies for analyzing Java code and to run the tests for the exercises and solutions.
    • From the Command Palette (Cmd/Ctrl+Shift+P), search for and run the command CodeQL: Install Pack Dependencies.
    • At the top of your VS Code window, type github in the box to filter the list.
    • Check the box next to cve-2021-21380-exercises, cve-2021-21380-exercises-tests, cve-2021-21380-solutions, and cve-2021-21380-solutions-tests.
    • Click OK/Enter.
  • Validate everything works as expected by running the tests for the solutions.
    • Open the view testing and press run tests (play icon is shown when hovering solutions) next to the solutions item in the tree.

Workshop

Learnings

The workshop is split into several exercises introducing the QL language support for Java and ends with a final query to find the known SQL injection. In these exercises you will learn:

  • How to reason about syntactic information.
  • How to reason about semantic information.
  • Explore the QL language support for Java to express patterns.
  • Explore how to reuse and extend existing modelling.
  • Use multiple building blocks to compose the final query.

Problem statement

In this workshop we will look for known SQL injection vulnerabilities in the XWiki Platform's ratings API component. Such vulnerabilities can occur in applications when information that is controlled by an external user makes its way to application code that insecurely construct a SQL query and executes it.

The known SQL injection discussed in this workshop is reviewed in GHSA-79rg-7mv3-jrr5 in GitHub Advisory Database. To find the SQL injection, and possible variants, we are going to the following sub-problems:

  • Identify the source of intrusted information and model it in QL.
  • Identify the sink, the method executing SQL queries, and model it in QL.
  • Combine the above solutions to determine if there is a flow of information between the source and the sink using taint tracking.

Exercises

In the first few exercises we will reason about syntactic information, using the Abstract Syntax Tree (AST), to identify:

  • the method described in the security advisory to build understanding of the vulnerability
  • parameters that contain untrusted data, our sources
  • method calls that accept SQL statements, our sinks

Exercise 1

Find all methods with the name getAverageRating and its declaring type in the program by completing the query exercise1.ql

Hints
  • The java module provides a class Method to reason about methods in a program.
  • The class Method provides the member predicates getName and hasName to reason about the name of a method.
  • The class Method provides the member getDeclaringType to reason about the type that declares the method.

A solution can be found in the query exercise1.ql

Intermezzo 1

A solution to exercise 1 returns a list of methods. Some of which are defined in an interface called RatingsManager and some which are defined in the classes AbstractRatingsManager and RatingsScriptService.

From the information returned by the query and XWiki component documentation we can deduce that:

  • XWiki uses a component oriented design to allow for extensions and customizations.
  • The vulnerable method is part of a component.
  • A component consist of an interface, annotated with Role, and an implementation annotated with Component.
  • A component that extends ScriptService are made accessible to wiki pages through scripting.

Exercise 2

Find all the classes annotated with the annotation Component by completing the query exercise2.ql. Note that the fully qualified name of the annotation's type is org.xwiki.component.annotation.Component.

Hints
  • The /class domain type/, the intersection of its super types, can be accessed using the keyword this in the /characteristic predicate/.
  • The Class class provides a method getAnAnnotation to get associated annotations.
  • The Annotation class provides the getType member predicate to reason about its type.
  • The Type class provides the member predicates getName and hasName to reason about the name of a type.
  • The RefType class, representing classes and interfaces, provides the member predicates getQualifiedName and hasQualifiedName to reason about the fully qualified name of the reftype.

A solution can be found in the query exercise2.ql

Exercise 3

Find all the components that implement the ScriptService interface by completing the query excercise3.ql

Hints
  • The Class type provides the member predicate getASuperType to reason about a class its super types, that is types it extends or implements.

A solution can be found in the query exercise3.ql

Intermezzo 2

Download Tool