Skip to content

Fix LDAPi vulnerability location when using ldapjs-promise #3593

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Aug 31, 2023

Conversation

CarlesDD
Copy link
Contributor

@CarlesDD CarlesDD commented Aug 29, 2023

What does this PR do?

Fixes the location for detected SQLi when code base uses ldapjs-promise lib

Motivation

Provide the correct location for detected vulnerabilities.

Plugin Checklist

  • Unit tests.

Additional Notes

There is an additional change in calculateDDBasePath util:

  • Previously DDBasePath was computed to project_root, which leads to the exclusion of traces from versions folder, used in plugins test.
  • Now it is computed to project_root/packages to avoid exclusion of traces from versions folder.

@github-actions
Copy link

github-actions bot commented Aug 29, 2023

Overall package size

Self size: 5.14 MB
Deduped: 59.18 MB
No deduping: 59.35 MB

Dependency sizes

name version self size total size
@datadog/native-iast-taint-tracking 1.5.0 14.86 MB 14.86 MB
@datadog/native-appsec 3.2.0 13.38 MB 13.39 MB
@datadog/pprof 3.2.0 10.8 MB 11.64 MB
protobufjs 7.2.4 2.74 MB 6.52 MB
@datadog/native-iast-rewriter 2.1.3 2.23 MB 2.32 MB
@opentelemetry/core 1.14.0 872.87 kB 1.47 MB
@datadog/native-metrics 2.0.0 898.77 kB 1.3 MB
@opentelemetry/api 1.4.1 780.32 kB 780.32 kB
import-in-the-middle 1.4.2 41.4 kB 704.79 kB
msgpack-lite 0.1.26 201.16 kB 281.59 kB
opentracing 0.14.7 194.81 kB 194.81 kB
semver 7.5.4 93.4 kB 123.8 kB
@datadog/sketches-js 2.1.0 109.9 kB 109.9 kB
lodash.sortby 4.7.0 75.76 kB 75.76 kB
lru-cache 7.14.0 74.95 kB 74.95 kB
ipaddr.js 2.1.0 60.23 kB 60.23 kB
ignore 5.2.4 51.22 kB 51.22 kB
int64-buffer 0.1.10 49.18 kB 49.18 kB
istanbul-lib-coverage 3.2.0 29.34 kB 29.34 kB
lodash.uniq 4.5.0 25.01 kB 25.01 kB
limiter 1.1.5 23.17 kB 23.17 kB
retry 0.13.1 18.85 kB 18.85 kB
lodash.kebabcase 4.1.1 17.75 kB 17.75 kB
node-abort-controller 3.1.1 16.89 kB 16.89 kB
lodash.pick 4.4.0 16.33 kB 16.33 kB
crypto-randomuuid 1.0.0 11.18 kB 11.18 kB
diagnostics_channel 1.1.0 7.07 kB 7.07 kB
path-to-regexp 0.1.7 6.78 kB 6.78 kB
koalas 1.0.2 6.47 kB 6.47 kB
methods 1.1.2 5.29 kB 5.29 kB
module-details-from-path 1.0.3 4.47 kB 4.47 kB

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@codecov
Copy link

codecov bot commented Aug 29, 2023

Codecov Report

Merging #3593 (a290bed) into master (5491b44) will increase coverage by 0.05%.
Report is 9 commits behind head on master.
The diff coverage is 100.00%.

@@            Coverage Diff             @@
##           master    #3593      +/-   ##
==========================================
+ Coverage   84.36%   84.41%   +0.05%     
==========================================
  Files         218      218              
  Lines        8830     8879      +49     
  Branches       33       33              
==========================================
+ Hits         7449     7495      +46     
- Misses       1381     1384       +3     
Files Changed Coverage Δ
...c/appsec/iast/analyzers/ldap-injection-analyzer.js 100.00% <100.00%> (ø)
packages/dd-trace/src/util.js 95.23% <100.00%> (ø)

... and 7 files with indirect coverage changes

📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more

@CarlesDD CarlesDD force-pushed the ccapell/fix-ldapjs-promise-vuln-location branch from a2acbc2 to a290bed Compare August 29, 2023 14:15
@pr-commenter
Copy link

pr-commenter bot commented Aug 29, 2023

Benchmarks

Benchmark execution time: 2023-08-29 14:24:37

Comparing candidate commit a290bed in PR branch ccapell/fix-ldapjs-promise-vuln-location with baseline commit 5491b44 in branch master.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 472 metrics, 20 unstable metrics.

@CarlesDD CarlesDD marked this pull request as ready for review August 29, 2023 15:12
@CarlesDD CarlesDD requested review from a team as code owners August 29, 2023 15:12
@CarlesDD CarlesDD merged commit 42668cc into master Aug 31, 2023
khanayan123 pushed a commit that referenced this pull request Sep 7, 2023
khanayan123 pushed a commit that referenced this pull request Sep 7, 2023
This was referenced Sep 7, 2023
khanayan123 pushed a commit that referenced this pull request Sep 8, 2023
khanayan123 pushed a commit that referenced this pull request Sep 8, 2023
@khanayan123 khanayan123 mentioned this pull request Sep 26, 2023
@tlhunter tlhunter deleted the ccapell/fix-ldapjs-promise-vuln-location branch January 19, 2024 22:17
watson added a commit that referenced this pull request May 26, 2025
When an error is logged, its message is redacted unless it's originating
from with the tracer.

Previously it would only detect it as coming from within the tracer if
the filepath was within the `packages` directory. This meant that some
errors originating from the tracer would be redacted even though they
shouldn't.

This problem can be traced back to the following PR:

    #3593
watson added a commit that referenced this pull request May 26, 2025
When an error is logged, its message is redacted unless it's originating
from with the tracer.

Previously it would only detect it as coming from within the tracer if
the filepath was within the `packages` directory. This meant that some
errors originating from the tracer would be redacted even though they
shouldn't.

This problem can be traced back to the following PR:

    #3593
watson added a commit that referenced this pull request May 26, 2025
When an error is logged, its message is redacted unless it's originating
from with the tracer.

Previously it would only detect it as coming from within the tracer if
the filepath was within the `packages` directory. This meant that some
errors originating from the tracer would be redacted even though they
shouldn't.

This problem can be traced back to the following PR:

    #3593
watson added a commit that referenced this pull request May 26, 2025
When an error is logged, its message is redacted unless it's originating
from with the tracer.

Previously it would only detect it as coming from within the tracer if
the filepath was within the `packages` directory. This meant that some
errors originating from the tracer would be redacted even though they
shouldn't.

This problem can be traced back to the following PR:

    #3593
watson added a commit that referenced this pull request May 28, 2025
When an error is logged, its message is redacted unless it's originating
from with the tracer.

Previously it would only detect it as coming from within the tracer if
the filepath was within the `packages` directory. This meant that some
errors originating from the tracer would be redacted even though they
shouldn't.

This problem can be traced back to the following PR:

    #3593
watson added a commit that referenced this pull request Jun 7, 2025
When an error is logged, its message is redacted unless it's originating
from with the tracer.

Previously it would only detect it as coming from within the tracer if
the filepath was within the `packages` directory. This meant that some
errors originating from the tracer would be redacted even though they
shouldn't.

This problem can be traced back to the following PR:

    #3593
watson added a commit that referenced this pull request Jun 20, 2025
When an error is logged, its message is redacted unless it's originating
from with the tracer.

Previously it would only detect it as coming from within the tracer if
the filepath was within the `packages` directory. This meant that some
errors originating from the tracer would be redacted even though they
shouldn't.

This problem can be traced back to the following PR:

    #3593
watson added a commit that referenced this pull request Jun 20, 2025
When an error is logged, its message is redacted unless it's originating
from with the tracer.

Previously it would only detect it as coming from within the tracer if
the filepath was within the `packages` directory. This meant that some
errors originating from the tracer would be redacted even though they
shouldn't.

This problem can be traced back to the following PR:

    #3593

Co-authored-by: Ugaitz Urien <ugaitz.urien@datadoghq.com>
dd-trace-js bot pushed a commit that referenced this pull request Jun 21, 2025
When an error is logged, its message is redacted unless it's originating
from with the tracer.

Previously it would only detect it as coming from within the tracer if
the filepath was within the `packages` directory. This meant that some
errors originating from the tracer would be redacted even though they
shouldn't.

This problem can be traced back to the following PR:

    #3593

Co-authored-by: Ugaitz Urien <ugaitz.urien@datadoghq.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants