Skip to content

Insecure cookie vulnerability detection#3184

Merged
uurien merged 13 commits into
masterfrom
ugaitz/insecure-cookie
Jun 1, 2023
Merged

Insecure cookie vulnerability detection#3184
uurien merged 13 commits into
masterfrom
ugaitz/insecure-cookie

Conversation

@uurien

@uurien uurien commented May 24, 2023

Copy link
Copy Markdown
Contributor

What does this PR do?

When we detect that set-cookie header is set without the Secure property it identifies INSECURE_COOKIE vulnerability and that is reported.

Plugin Checklist

  • Unit tests.

Additional Notes

Note for non appsec reviewers:

To be able to detect that headers are set, when IAST is active res.setHeader method is instrumented and an event in a new channel is published.

@github-actions

github-actions Bot commented May 24, 2023

Copy link
Copy Markdown
Contributor

Overall package size

Self size: 4.21 MB
Deduped: 58.41 MB
No deduping: 58.45 MB

Dependency sizes

name version self size total size
@datadog/pprof 2.2.1 14.24 MB 15.12 MB
@datadog/native-iast-taint-tracking 1.4.1 14.85 MB 14.86 MB
@datadog/native-appsec 3.2.0 13.38 MB 13.39 MB
protobufjs 7.1.2 2.76 MB 6.55 MB
@datadog/native-iast-rewriter 2.0.1 2.09 MB 2.1 MB
@datadog/native-metrics 2.0.0 898.77 kB 1.3 MB
opentracing 0.14.7 194.81 kB 194.81 kB
semver 7.3.8 88.2 kB 118.6 kB
@datadog/sketches-js 2.1.0 109.9 kB 109.9 kB
lodash.sortby 4.7.0 75.76 kB 75.76 kB
lru-cache 7.14.0 74.95 kB 74.95 kB
ipaddr.js 2.0.1 59.52 kB 59.52 kB
ignore 5.2.0 48.87 kB 48.87 kB
import-in-the-middle 1.3.5 34.34 kB 38.81 kB
istanbul-lib-coverage 3.2.0 29.34 kB 29.34 kB
retry 0.10.1 27.44 kB 27.44 kB
lodash.uniq 4.5.0 25.01 kB 25.01 kB
limiter 1.1.5 23.17 kB 23.17 kB
lodash.kebabcase 4.1.1 17.75 kB 17.75 kB
lodash.pick 4.4.0 16.33 kB 16.33 kB
node-abort-controller 3.0.1 14.33 kB 14.33 kB
crypto-randomuuid 1.0.0 11.18 kB 11.18 kB
diagnostics_channel 1.1.0 7.07 kB 7.07 kB
path-to-regexp 0.1.7 6.78 kB 6.78 kB
koalas 1.0.2 6.47 kB 6.47 kB
methods 1.1.2 5.29 kB 5.29 kB
module-details-from-path 1.0.3 4.47 kB 4.47 kB

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@codecov

codecov Bot commented May 24, 2023

Copy link
Copy Markdown

Codecov Report

Merging #3184 (a51df1c) into master (0c64dfc) will increase coverage by 0.02%.
The diff coverage is 91.17%.

@@            Coverage Diff             @@
##           master    #3184      +/-   ##
==========================================
+ Coverage   86.49%   86.52%   +0.02%     
==========================================
  Files         335      337       +2     
  Lines       11974    12020      +46     
  Branches       33       33              
==========================================
+ Hits        10357    10400      +43     
- Misses       1617     1620       +3     
Impacted Files Coverage Δ
packages/dd-trace/src/appsec/channels.js 100.00% <ø> (ø)
...es/dd-trace/src/appsec/iast/analyzers/analyzers.js 100.00% <ø> (ø)
...ckages/dd-trace/src/appsec/iast/vulnerabilities.js 100.00% <ø> (ø)
...dd-trace/src/appsec/iast/vulnerability-reporter.js 100.00% <ø> (ø)
...ckages/datadog-instrumentations/src/http/server.js 80.00% <25.00%> (-11.90%) ⬇️
...ckages/dd-trace/src/appsec/iast/analyzers/index.js 100.00% <100.00%> (ø)
.../appsec/iast/analyzers/insecure-cookie-analyzer.js 100.00% <100.00%> (ø)
...c/iast/analyzers/set-cookies-header-interceptor.js 100.00% <100.00%> (ø)
...rc/appsec/iast/analyzers/sql-injection-analyzer.js 79.48% <100.00%> (+0.53%) ⬆️
...rc/appsec/iast/analyzers/vulnerability-analyzer.js 83.33% <100.00%> (+4.26%) ⬆️
... and 1 more

... and 2 files with indirect coverage changes

📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more

@pr-commenter

pr-commenter Bot commented May 24, 2023

Copy link
Copy Markdown

Benchmarks

Comparing candidate commit a51df1c in PR branch ugaitz/insecure-cookie with baseline commit 0c64dfc in branch master.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 448 metrics, 24 unstable metrics.

@uurien
uurien marked this pull request as ready for review May 24, 2023 16:56
@uurien
uurien requested review from a team as code owners May 24, 2023 16:56
Comment thread packages/dd-trace/src/appsec/iast/analyzers/intermendiate-cookies-analyzer.js Outdated
Comment thread packages/dd-trace/src/appsec/iast/analyzers/intermendiate-cookies-analyzer.js Outdated
Comment thread packages/dd-trace/src/appsec/iast/analyzers/intermendiate-cookies-analyzer.js Outdated
@uurien
uurien force-pushed the ugaitz/insecure-cookie branch 2 times, most recently from 6695d89 to 0c9e3dc Compare May 25, 2023 15:49
@uurien
uurien requested a review from CarlesDD May 25, 2023 15:50
@uurien
uurien force-pushed the ugaitz/insecure-cookie branch from 0c9e3dc to e34ca46 Compare May 29, 2023 07:24
CarlesDD
CarlesDD previously approved these changes May 29, 2023
Comment thread packages/dd-trace/src/appsec/iast/analyzers/index.js Outdated
iunanua
iunanua previously approved these changes May 30, 2023
Comment thread packages/dd-trace/src/appsec/iast/analyzers/insecure-cookie-analyzer.js Outdated
@uurien
uurien requested a review from a team May 30, 2023 15:29
Comment thread packages/dd-trace/src/appsec/iast/analyzers/sql-injection-analyzer.js Outdated
@uurien
uurien dismissed stale reviews from iunanua and CarlesDD via 6e7d8af May 30, 2023 15:55
iunanua
iunanua previously approved these changes May 31, 2023
rochdev
rochdev previously approved these changes May 31, 2023
@uurien
uurien dismissed stale reviews from rochdev and iunanua via a51df1c June 1, 2023 06:32
@uurien
uurien force-pushed the ugaitz/insecure-cookie branch from 6e7d8af to a51df1c Compare June 1, 2023 06:32
@uurien
uurien merged commit 40157d3 into master Jun 1, 2023
@uurien
uurien deleted the ugaitz/insecure-cookie branch June 1, 2023 06:46
uurien pushed a commit that referenced this pull request Jun 1, 2023
* Initial version of insecure-cookie vulnerability

* Small fix

* Add tests

* rename const

* Fix test

* Exclude express file from insecure cookie stack trace

* Some code styles + tests

* Small code spaces

* intermediate-cookies-analyzer to set-cookies-header-intercepteor

* Comments in the PR

* Comments in PR

* Ignore insecure cookie when cookie value is empty

* Reuse excluded paths array
uurien pushed a commit that referenced this pull request Jun 1, 2023
* Initial version of insecure-cookie vulnerability

* Small fix

* Add tests

* rename const

* Fix test

* Exclude express file from insecure cookie stack trace

* Some code styles + tests

* Small code spaces

* intermediate-cookies-analyzer to set-cookies-header-intercepteor

* Comments in the PR

* Comments in PR

* Ignore insecure cookie when cookie value is empty

* Reuse excluded paths array
uurien pushed a commit that referenced this pull request Jun 1, 2023
* Initial version of insecure-cookie vulnerability

* Small fix

* Add tests

* rename const

* Fix test

* Exclude express file from insecure cookie stack trace

* Some code styles + tests

* Small code spaces

* intermediate-cookies-analyzer to set-cookies-header-intercepteor

* Comments in the PR

* Comments in PR

* Ignore insecure cookie when cookie value is empty

* Reuse excluded paths array
This was referenced Jun 1, 2023
uurien pushed a commit that referenced this pull request Jun 2, 2023
* Initial version of insecure-cookie vulnerability

* Small fix

* Add tests

* rename const

* Fix test

* Exclude express file from insecure cookie stack trace

* Some code styles + tests

* Small code spaces

* intermediate-cookies-analyzer to set-cookies-header-intercepteor

* Comments in the PR

* Comments in PR

* Ignore insecure cookie when cookie value is empty

* Reuse excluded paths array
uurien pushed a commit that referenced this pull request Jun 2, 2023
* Initial version of insecure-cookie vulnerability

* Small fix

* Add tests

* rename const

* Fix test

* Exclude express file from insecure cookie stack trace

* Some code styles + tests

* Small code spaces

* intermediate-cookies-analyzer to set-cookies-header-intercepteor

* Comments in the PR

* Comments in PR

* Ignore insecure cookie when cookie value is empty

* Reuse excluded paths array
uurien pushed a commit that referenced this pull request Jun 2, 2023
* Initial version of insecure-cookie vulnerability

* Small fix

* Add tests

* rename const

* Fix test

* Exclude express file from insecure cookie stack trace

* Some code styles + tests

* Small code spaces

* intermediate-cookies-analyzer to set-cookies-header-intercepteor

* Comments in the PR

* Comments in PR

* Ignore insecure cookie when cookie value is empty

* Reuse excluded paths array
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants