OWASP/OpenCRE

Input validation missing on import csv functionality

オープン

#554 opened on 2024/09/18

 (8 件のコメント) (0 件のリアクション) (1 人の担当者)Python (116 件のフォーク)auto 404
GSOCenhancementgood first issue

Repository metrics

Stars
 (167 個のスター)
PR merge metrics
 (PR metrics pending)

説明

Issue

When importing a new standard, no validation is performed on the imported csv file, a generic non-descriptive "500 - Internal Server Error" is returned or new CREs are wrongfully injected.

More specifically, in the outlined case, if the format of "CRE 0" column is XX-XXX| instead of XXX-XXX|, a non-descriptive error is returned. Also, I noticed that if in the "<standard_name>|name" column the requirement's text is enclosed between three double quotes '"""', the csv is treated as valid and the whole row is entered as a new root CRE.

image

コントリビューターガイド