Project

General

Profile

Actions

Bug #22801

closed

Directive CSV compliance is not correctly quote-escaped

Added by François ARMAND about 1 year ago. Updated 12 months ago.

Status:
Released
Priority:
N/A
Category:
Security
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
Checked
Regression:
No

Description

If there's " in values, they are not escaped.

Example (see around TLS_RSA_WITH_DES_CBC_SHA):

"Basic hardening on all systems", "Check Cipher TLS_RSA_WITH_DES_CBC_SHA", "Audit from Powershell execution", "prod-app-01.lab.rudder.io", "(Get-TlsCipherSuite -Name "TLS_RSA_WITH_DES_CBC_SHA").Count", "auditNotApplicable", "'Audit from Powershell execution' method is not available on Linux Rudder agent, skip was not applicable" 
Actions #1

Updated by François ARMAND about 1 year ago

  • Description updated (diff)
Actions #2

Updated by François ARMAND about 1 year ago

  • Status changed from New to In progress
Actions #3

Updated by François ARMAND about 1 year ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from François ARMAND to Vincent MEMBRÉ
  • Pull Request set to https://github.com/Normation/rudder/pull/4806
Actions #4

Updated by Anonymous 12 months ago

  • Status changed from Pending technical review to Pending release
Actions #5

Updated by Elaad FURREEDAN 12 months ago

  • Fix check changed from To do to Checked
Actions #6

Updated by Vincent MEMBRÉ 12 months ago

  • Status changed from Pending release to Released

This bug has been fixed in Rudder 7.3.3 which was released today.

Actions

Also available in: Atom PDF