Repository navigation
Expand file tree
/
Copy pathdetect-vulnerable-config-writes.ts
More file actions
74 lines (69 loc) · 3.58 KB
/
Copy pathdetect-vulnerable-config-writes.ts
File metadata and controls
74 lines (69 loc) · 3.58 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
import type { ParsedConfigActivity } from '../args/parse-argv.types';
import type { Vulnerability, VulnerabilityCategory } from './vulnerability.types';
export function* detectVulnerableConfigWrites({
write,
}: ParsedConfigActivity): Generator<Vulnerability> {
for (const config of write) {
for (const helper of preventUnsafeConfig) {
const vulnerability = helper(config.key);
if (vulnerability) {
yield vulnerability;
}
}
}
}
function preventConfigBuilder(
config: string | RegExp,
category: VulnerabilityCategory,
message = String(config)
) {
const regex = typeof config === 'string' ? new RegExp(`\\s*${config.toLowerCase()}`) : config;
return function preventCommand(key: string): Vulnerability | void {
if (regex.test(key)) {
return {
category,
message: `Configuring ${message} is not permitted without enabling ${category}`,
};
}
};
}
function preventExpandedConfigBuilder(config: string, category: VulnerabilityCategory) {
const regex = new RegExp(`\\s*${config.toLowerCase().replace(/\./g, '(..+)?.')}`);
return preventConfigBuilder(regex, category, config);
}
const preventUnsafeConfig = [
preventConfigBuilder('alias', 'allowUnsafeAlias'),
preventConfigBuilder('core.askPass', 'allowUnsafeAskPass'),
preventConfigBuilder('core.editor', 'allowUnsafeEditor'),
preventConfigBuilder('core.fsmonitor', 'allowUnsafeFsMonitor'),
preventConfigBuilder('core.gitProxy', 'allowUnsafeGitProxy'),
preventConfigBuilder('core.hooksPath', 'allowUnsafeHooksPath'),
preventConfigBuilder('core.pager', 'allowUnsafePager'),
preventConfigBuilder('core.sshCommand', 'allowUnsafeSshCommand'),
preventExpandedConfigBuilder('credential.helper', 'allowUnsafeCredentialHelper'),
preventExpandedConfigBuilder('diff.command', 'allowUnsafeDiffExternal'),
preventConfigBuilder('diff.external', 'allowUnsafeDiffExternal'),
preventExpandedConfigBuilder('difftool.cmd', 'allowUnsafeDiffExternal'),
preventExpandedConfigBuilder('diff.textconv', 'allowUnsafeDiffTextConv'),
preventExpandedConfigBuilder('filter.clean', 'allowUnsafeFilter'),
preventExpandedConfigBuilder('filter.process', 'allowUnsafeFilter'),
preventExpandedConfigBuilder('filter.smudge', 'allowUnsafeFilter'),
preventExpandedConfigBuilder('gpg.program', 'allowUnsafeGpgProgram'),
preventConfigBuilder('include.path', 'allowUnsafeInclude'),
preventExpandedConfigBuilder('includeIf', 'allowUnsafeInclude'),
preventConfigBuilder('init.templateDir', 'allowUnsafeTemplateDir'),
preventExpandedConfigBuilder('pager.', 'allowUnsafePager'),
preventExpandedConfigBuilder('merge.driver', 'allowUnsafeMergeDriver'),
preventExpandedConfigBuilder('mergetool.path', 'allowUnsafeMergeDriver'),
preventExpandedConfigBuilder('mergetool.cmd', 'allowUnsafeMergeDriver'),
preventExpandedConfigBuilder('protocol.allow', 'allowUnsafeProtocolOverride'),
preventExpandedConfigBuilder('remote.receivepack', 'allowUnsafePack'),
preventExpandedConfigBuilder('remote.uploadpack', 'allowUnsafePack'),
preventConfigBuilder('uploadpack.packObjectsHook', 'allowUnsafePack'),
preventConfigBuilder('sequence.editor', 'allowUnsafeEditor'),
preventExpandedConfigBuilder('submodule.update', 'allowUnsafeSubmodule'),
preventExpandedConfigBuilder('tar.command', 'allowUnsafeCommandBinaries'),
preventExpandedConfigBuilder('trailer.cmd', 'allowUnsafeCommandBinaries'),
preventExpandedConfigBuilder('trailer.command', 'allowUnsafeCommandBinaries'),
preventExpandedConfigBuilder('url.insteadOf', 'allowUnsafeUrlRewrite'),
];