OWASP/OpenCRE

Input validation missing on import csv functionality

Offen

#554 geöffnet am 18.09.2024

 (8 Kommentare) (0 Reaktionen) (1 zugewiesene Person)Python (116 Forks)auto 404
GSOCenhancementgood first issue

Repository-Metriken

Stars
 (167 Sterne)
PR-Merge-Metriken
 (PR-Metriken ausstehend)

Beschreibung

Issue

When importing a new standard, no validation is performed on the imported csv file, a generic non-descriptive "500 - Internal Server Error" is returned or new CREs are wrongfully injected.

More specifically, in the outlined case, if the format of "CRE 0" column is XX-XXX| instead of XXX-XXX|, a non-descriptive error is returned. Also, I noticed that if in the "<standard_name>|name" column the requirement's text is enclosed between three double quotes '"""', the csv is treated as valid and the whole row is entered as a new root CRE.

image

Contributor Guide