-
Notifications
You must be signed in to change notification settings - Fork 403
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(api): Code scanning alerts #254
Conversation
unique_key = locals()['AutoDiscovery']().unique_key | ||
attrs = locals()['AutoDiscovery']().attributes() or [] | ||
local_ns = {} | ||
exec(x, {}, local_ns) |
Check failure
Code scanning / CodeQL
Code injection Critical
user-provided value
This code execution depends on a
user-provided value
@@ -312,7 +313,7 @@ | |||
start = time.time() | |||
execute = db.session.execute | |||
# current_app.logger.debug(v_query_sql) | |||
res = execute(v_query_sql).fetchall() | |||
res = execute(text(v_query_sql)).fetchall() |
Check failure
Code scanning / CodeQL
SQL query built from user-controlled sources High
user-provided value
This SQL query depends on a
user-provided value
This SQL query depends on a
user-provided value
This SQL query depends on a
user-provided value
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
@@ -525,7 +526,7 @@ | |||
if k: | |||
table_name = TableMap(attr=attr).table_name | |||
query_sql = FACET_QUERY.format(table_name, self.query_sql, attr.id) | |||
result = db.session.execute(query_sql).fetchall() | |||
result = db.session.execute(text(query_sql)).fetchall() |
Check failure
Code scanning / CodeQL
SQL query built from user-controlled sources High
user-provided value
This SQL query depends on a
user-provided value
This SQL query depends on a
user-provided value
This SQL query depends on a
user-provided value
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
This SQL query depends on a user-provided value.
No description provided.