mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
[release/v7.4] Add CodeQL suppressions for PowerShell intended behavior (#25376)
Co-authored-by: Anam Navied <anam.naviyou@gmail.com> Co-authored-by: Travis Plunk <travis.plunk@microsoft.com>
This commit is contained in:
co-authored by
Anam Navied
Travis Plunk
parent
a2f1b7f4b2
commit
ee53c67b9d
@@ -684,6 +684,7 @@ namespace Microsoft.PowerShell.Commands
|
||||
{
|
||||
// CoreCLR doesn't allow re-load TPA assemblies with different API (i.e. we load them by name and now want to load by path).
|
||||
// LoadAssemblyHelper helps us avoid re-loading them, if they already loaded.
|
||||
// codeql[cs/dll-injection-remote] - This is expected PowerShell behavior and integral to the purpose of the class. It allows users to load any C# dependencies they need for their PowerShell application and add other types they require.
|
||||
Assembly assembly = LoadAssemblyHelper(assemblyName) ?? Assembly.LoadFrom(ResolveAssemblyName(assemblyName, false));
|
||||
|
||||
if (PassThru)
|
||||
|
||||
+1
@@ -1792,6 +1792,7 @@ namespace Microsoft.PowerShell.Commands
|
||||
ContentDispositionHeaderValue contentDisposition = new("form-data");
|
||||
contentDisposition.Name = LanguagePrimitives.ConvertTo<string>(fieldName);
|
||||
|
||||
// codeql[cs/information-exposure-through-exception] - PowerShell is an on-premise product, meaning local users would already have access to the binaries and stack traces. Therefore, the information would not be exposed in the same way it would be for an ASP .NET service.
|
||||
StringContent result = new(LanguagePrimitives.ConvertTo<string>(fieldValue));
|
||||
result.Headers.ContentDisposition = contentDisposition;
|
||||
|
||||
|
||||
@@ -1385,6 +1385,7 @@ namespace System.Management.Automation
|
||||
{
|
||||
try
|
||||
{
|
||||
// codeql[cs/dll-injection-remote] - The dll is loaded during the initial state setup, which is expected behavior. This allows users hosting PowerShell to load additional C# types to enable their specific scenarios.
|
||||
loadedAssembly = Assembly.LoadFrom(filePath);
|
||||
return loadedAssembly;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user