ApolloAuto / apollo

An open autonomous driving platform
Apache License 2.0
24.71k stars 9.62k forks source link

请问,这类codeql的提示值得处理吗? #15412

Open zhanghaomingzhennanqu opened 1 month ago

zhanghaomingzhennanqu commented 1 month ago

System information

Steps to reproduce the issue:

Supporting materials (screenshots, command lines, code/script snippets):

屏幕截图 2024-05-26 232649 codeql提到, missing-origin-check会: Missing origin verification in a postMessage handler allows any windows to send arbitrary data to the handler. overly-large-range会: Overly permissive regular expression ranges match a wider range of characters than intended. This may allow an attacker to bypass a filter or sanitizer. 这两个好像都跟CWE-20有关。