-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Open
Labels
questionFurther information is requestedFurther information is requested
Description
Description
CodeQL currently does not detect CWE-208 (Observable Timing Discrepancy) in JavaScript/TypeScript, while this weakness is covered in Java/Kotlin, Python and Ruby. This appears to be a language coverage gap rather than a configuration issue. [https://codeql.github.com/codeql-query-help/full-cwe/]
Example
In authentication or validation logic, I would expect CodeQL to at least be able
to model potential timing differences, for example:
if (value !== expectedValue) {
return res.status(401).json({ message: 'Invalid token' });
}Question
Is there a plan to expand CodeQL query coverage for this weakness in the remaining languages?
Metadata
Metadata
Assignees
Labels
questionFurther information is requestedFurther information is requested