SonarQube - Function constructors should not be used

Viewed 374

I am using SonarQube scan for ASP.NET MVC project for code quality inspection. SonarQube shows vulnerability error for one of the javascript library used in project. i.e - datepicker.js

error - Review this "Function" call and make sure its arguments are properly validated.

below is code from datepicker.js -

(function(){
  var cache = {};
 
  this.tmpl = function tmpl(str, data){
    // Figure out if we're getting a template, or if we need to
    // load the template - and be sure to cache the result.
    var fn = !/\W/.test(str) ?
      cache[str] = cache[str] ||
        tmpl(document.getElementById(str).innerHTML) :
     
      // Generate a reusable function that will serve as a template
      // generator (and which will be cached).
      new Function("obj",
        "var p=[],print=function(){p.push.apply(p,arguments);};" +
       
        // Introduce the data as local variables using with(){}
        "with(obj){p.push('" +
       
        // Convert the template into pure JavaScript
        str
          .replace(/[\r\t\n]/g, " ")
          .split("<%").join("\t")
          .replace(/((^|%>)[^\t]*)'/g, "$1\r")
          .replace(/\t=(.*?)%>/g, "',$1,'")
          .split("\t").join("');")
          .split("%>").join("p.push('")
          .split("\r").join("\\'")
      + "');}return p.join('');");
   
    // Provide some basic currying to the user
    return data ? fn( data ) : fn;
  };
})

here vulnerability is shown for function constructor used -

new Function("obj",
            "var p=[],print=function(){p.push.apply(p,arguments);};" +
           
            // Introduce the data as local variables using with(){}

Resolution - it has also provided solution. it says, You should use ECMAScript 5's built-in JSON functions or a dedicated library.

link - https://rules.sonarsource.com/javascript/RSPEC-3523

which alternatives can be used in place of new Function("param1","param2") to pass sonar scan?

0 Answers
Related