OWASP/OpenCRE

Input validation missing on import csv functionality

Ouverte

#554 ouverte le 18 sept. 2024

 (8 commentaires) (0 réaction) (1 personne assignée)Python (116 forks)auto 404
GSOCenhancementgood first issue

Métriques du dépôt

Stars
 (167 étoiles)
Métriques de merge PR
 (Métriques PR en attente)

Description

Issue

When importing a new standard, no validation is performed on the imported csv file, a generic non-descriptive "500 - Internal Server Error" is returned or new CREs are wrongfully injected.

More specifically, in the outlined case, if the format of "CRE 0" column is XX-XXX| instead of XXX-XXX|, a non-descriptive error is returned. Also, I noticed that if in the "<standard_name>|name" column the requirement's text is enclosed between three double quotes '"""', the csv is treated as valid and the whole row is entered as a new root CRE.

image

Guide contributeur