OWASP/OpenCRE

Input validation missing on import csv functionality

Aberta

#554 aberto em 18 de set. de 2024

 (8 comentários) (0 reação) (1 responsável)Python (116 forks)auto 404
GSOCenhancementgood first issue

Métricas do repositório

Stars
 (167 estrelas)
Métricas de merge de PR
 (Métricas PR pendentes)

Description

Issue

When importing a new standard, no validation is performed on the imported csv file, a generic non-descriptive "500 - Internal Server Error" is returned or new CREs are wrongfully injected.

More specifically, in the outlined case, if the format of "CRE 0" column is XX-XXX| instead of XXX-XXX|, a non-descriptive error is returned. Also, I noticed that if in the "<standard_name>|name" column the requirement's text is enclosed between three double quotes '"""', the csv is treated as valid and the whole row is entered as a new root CRE.

image

Guia do colaborador