OWASP/OpenCRE

Input validation missing on import csv functionality

Open

#554 opened on Sep 18, 2024

 (8 comments) (0 reactions) (1 assignee)Python (116 forks)auto 404
GSOCenhancementgood first issue

Repository metrics

Stars
 (167 stars)
PR merge metrics
 (PR metrics pending)

Description

Issue

When importing a new standard, no validation is performed on the imported csv file, a generic non-descriptive "500 - Internal Server Error" is returned or new CREs are wrongfully injected.

More specifically, in the outlined case, if the format of "CRE 0" column is XX-XXX| instead of XXX-XXX|, a non-descriptive error is returned. Also, I noticed that if in the "<standard_name>|name" column the requirement's text is enclosed between three double quotes '"""', the csv is treated as valid and the whole row is entered as a new root CRE.

image

Contributor guide