ghas-to-csv vulnerable to Improper Neutralization of Formula Elements in a CSV File
Moderate severity
GitHub Reviewed
Published
Sep 16, 2022
in
advanced-security/ghas-to-csv
•
Updated Jan 28, 2023
Description
Published to the GitHub Advisory Database
Sep 16, 2022
Reviewed
Sep 16, 2022
Published by the National Vulnerability Database
Sep 17, 2022
Last updated
Jan 28, 2023
Impact
This GitHub Action creates a CSV file without sanitizing the output of the APIs. If an alert is dismissed or any other custom field contains executable code / formulas, it might be run when an endpoint opens that CSV file in a spreadsheet program. The data flow looks like this 👇🏻
Patches
Please use version
v1
or later. That tag moves from usingcsv
todefusedcsv
to mitigate this problem.Workarounds
There is no workaround. Please upgrade to using the latest tag,
v1
(or later).References
defusedcsv
hereFor more information
If you have any questions or comments about this advisory:
References