Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

关于byte和Byte类型的参数作为污点疑问 #116

Open
testnet0 opened this issue Nov 14, 2024 · 1 comment
Open

关于byte和Byte类型的参数作为污点疑问 #116

testnet0 opened this issue Nov 14, 2024 · 1 comment

Comments

@testnet0
Copy link

从实际情况,代码中byte和Byte类型不太可能被利用执行漏洞,为什么要作为污点
image

@alipaydeshui
Copy link
Collaborator

从实际情况,代码中byte和Byte类型不太可能被利用执行漏洞,为什么要作为污点 image

感谢反馈~
Byte作为漏洞利用确实不太可能,我们考虑一下如何修改
我们这里列出来这个case是因为我们不但用这个benchmark来测试sast/iast,还用来测试程序分析的底层引擎(不仅仅用于安全漏洞检测,还用于质量分析等),所以把Byte这类数据的跟踪也纳入进来了。
作为sast/iast的用户,可以先忽略这个case

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants