GHSA-634p-93h9-92vh

    Dashboard / Vulnerabilities / GHSA-634p-93h9-92vh

    GHSA-634p-93h9-92vh

    Published: 16 Sept 2022Last Modified: 8 Nov 2023

    Summary: ghas-to-csv vulnerable to Improper Neutralization of Formula Elements in a CSV File

    Details: ### Impact This GitHub Action creates a CSV file without sanitizing the output of the APIs. If an alert is dismissed or any other custom field contains executable code / formulas, it might be run when an endpoint opens that CSV file in a spreadsheet program. The data flow looks like this 👇🏻 ```mermaid graph TD A(Repository) -->|developer dismissal, other data input| B(GitHub Advanced Security data) B -->|ghas-to-csv| C(CSV file) C -->|spreadsheet program| D(endpoint executes potentially malicious code) ``` ### Patches Please use version `v1` or later. That tag moves from using `csv` to `defusedcsv` to mitigate this problem. ### Workarounds There is no workaround. Please upgrade to using the latest tag, `v1` (or later). ### References * CWE-1236 information from [MITRE](https://cwe.mitre.org/data/definitions/1236.html) * CSV injection information from [OWASP](https://owasp.org/www-community/attacks/CSV_Injection) * CodeQL query for CWE-1236 in Python [here](https://github.com/github/codeql/tree/main/python/ql/src/experimental/Security/CWE-1236) * PyPI site for `defusedcsv` [here](https://pypi.org/project/defusedcsv/) ### For more information If you have any questions or comments about this advisory: * Open an issue in this repository [here](https://github.com/some-natalie/ghas-to-csv/issues)

    Affected packages

    Package

    Name: some-natalie/ghas-to-csv

    Purl:

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-634p-93h9-92vh | CVE-DB