-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Open
Labels
questionFurther information is requestedFurther information is requested
Description
Does CodeQL have plans to implement automated detection of attempts to exploit the Trojan Source vulnerabilities that have been recently publicized?
https://krebsonsecurity.com/2021/11/trojan-source-bug-threatens-the-security-of-all-code/
For instance, it seems right now that CodeQL with security-and-quality
enabled does not raise any issues on the proof of concept repository for this security research paper: https://github.com/nickboucher/trojan-source
b1gb4dw0lf, danMateer and KIT-GregC
Metadata
Metadata
Assignees
Labels
questionFurther information is requestedFurther information is requested