OWASP/OpenCRE

Input validation missing on import csv functionality

开放

#554 创建于 2024年9月18日

 (8 条评论) (0 个反应) (1 位负责人)Python (116 个派生)auto 404
GSOCenhancementgood first issue

仓库指标

星标
 (167 个星标)
PR 合并指标
 (PR 指标待抓取)

描述

Issue

When importing a new standard, no validation is performed on the imported csv file, a generic non-descriptive "500 - Internal Server Error" is returned or new CREs are wrongfully injected.

More specifically, in the outlined case, if the format of "CRE 0" column is XX-XXX| instead of XXX-XXX|, a non-descriptive error is returned. Also, I noticed that if in the "<standard_name>|name" column the requirement's text is enclosed between three double quotes '"""', the csv is treated as valid and the whole row is entered as a new root CRE.

image

贡献者指南