[release/v7.4] Add Codeql Suppressions (#25973)

Co-authored-by: Anam Navied <anam.naviyou@gmail.com>
Co-authored-by: Travis Plunk <travis.plunk@microsoft.com>
This commit is contained in:
PowerShell Team Bot
2025-09-03 23:23:22 +00:00
committed by GitHub
co-authored by Anam Navied Travis Plunk
parent 98f26c68c5
commit b2d043aa93
5 changed files with 5 additions and 0 deletions
@@ -1926,6 +1926,7 @@ namespace Microsoft.PowerShell.Commands
}
catch (CommandNotFoundException)
{
// codeql[cs/microsoft/command-line-injection-shell-execution] - This is expected Poweshell behavior where user inputted paths are supported for the context of this method. The user assumes trust for the file path they are specifying and the process is on the user's system except for remoting in which case restricted remoting security guidelines should be used.
startInfo.FileName = FilePath;
#if UNIX
// Arguments are passed incorrectly to the executable used for ShellExecute and not to filename https://github.com/dotnet/corefx/issues/30718
@@ -1296,6 +1296,7 @@ namespace Microsoft.PowerShell.Commands
_cancelToken = new CancellationTokenSource();
try
{
// codeql[cs/ssrf] - This is expected Poweshell behavior where user inputted Uri is supported for the context of this method. The user assumes trust for the Uri and invocation is done on the user's machine, not a web application. If there is concern for remoting, they should use restricted remoting.
response = client.SendAsync(currentRequest, HttpCompletionOption.ResponseHeadersRead, _cancelToken.Token).GetAwaiter().GetResult();
}
catch (TaskCanceledException ex)
@@ -1397,6 +1397,7 @@ namespace System.Management.Automation
{
var startInfo = new ProcessStartInfo
{
// codeql[cs/microsoft/command-line-injection-shell-execution] - This is expected Poweshell behavior where user inputted paths are supported for the context of this method. The user assumes trust for the file path specified on the user's system to retrieve process info for, and in the case of remoting, restricted remoting security guidelines should be used.
FileName = this.Path
};
@@ -2230,6 +2230,7 @@ namespace System.Management.Automation.Runspaces
// linux|macos:
// Subsystem powershell /usr/local/bin/pwsh -SSHServerMode -NoLogo -NoProfile
// codeql[cs/microsoft/command-line-injection-shell-execution] - This is expected Poweshell behavior where user inputted paths are supported for the context of this method. The user assumes trust for the file path specified, so any file executed in the runspace would be in the user's local system/process or a system they have access to in which case restricted remoting security guidelines should be used.
System.Diagnostics.ProcessStartInfo startInfo = new System.Diagnostics.ProcessStartInfo(filePath);
// pass "-i identity_file" command line argument to ssh if KeyFilePath is set
@@ -1324,6 +1324,7 @@ namespace Microsoft.PowerShell.Commands
if (ShouldProcess(resource, action))
{
var invokeProcess = new System.Diagnostics.Process();
// codeql[cs/microsoft/command-line-injection-shell-execution] - This is expected Poweshell behavior where user inputted paths are supported for the context of this method. The user assumes trust for the file path they are specifying. If there is concern for remoting, restricted remoting guidelines should be used.
invokeProcess.StartInfo.FileName = path;
#if UNIX
bool useShellExecute = false;