Skip to content

[Python][Questions] CodeQL security query is not able to detect CWE from given bad example in repository.  #8555

@Kadam-Tushar

Description

@Kadam-Tushar

I have created codeql database of this python file https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/examples/tarslip_bad.py.
But when I analyze database using https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-022/TarSlip.ql this query, I see nothing in query results.

Can someone help me why codeql query is not able to detect CWE-22 from the given example?

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions