OWASP/OpenCRE

Input validation missing on import csv functionality

Aperta

#554 aperta il 18 set 2024

 (8 commenti) (0 reazioni) (1 assegnatario)Python (116 fork)auto 404
GSOCenhancementgood first issue

Metriche repository

Star
 (167 stelle)
Metriche merge PR
 (Metriche PR in attesa)

Descrizione

Issue

When importing a new standard, no validation is performed on the imported csv file, a generic non-descriptive "500 - Internal Server Error" is returned or new CREs are wrongfully injected.

More specifically, in the outlined case, if the format of "CRE 0" column is XX-XXX| instead of XXX-XXX|, a non-descriptive error is returned. Also, I noticed that if in the "<standard_name>|name" column the requirement's text is enclosed between three double quotes '"""', the csv is treated as valid and the whole row is entered as a new root CRE.

image

Guida contributor