Project

General

Profile

Actions

Bug #22801

open

Directive CSV compliance is not correctly quote-escaped

Added by François ARMAND 6 days ago. Updated 6 days ago.

Status:
Pending technical review
Priority:
N/A
Category:
Security
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Regression:
No

Description

If there's " in values, they are not escaped.

Example (see around TLS_RSA_WITH_DES_CBC_SHA):

"Basic hardening on all systems", "Check Cipher TLS_RSA_WITH_DES_CBC_SHA", "Audit from Powershell execution", "prod-app-01.lab.rudder.io", "(Get-TlsCipherSuite -Name "TLS_RSA_WITH_DES_CBC_SHA").Count", "auditNotApplicable", "'Audit from Powershell execution' method is not available on Linux Rudder agent, skip was not applicable" 
Actions #1

Updated by François ARMAND 6 days ago

  • Description updated (diff)
Actions #2

Updated by François ARMAND 6 days ago

  • Status changed from New to In progress
Actions #3

Updated by François ARMAND 6 days ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from François ARMAND to Vincent MEMBRÉ
  • Pull Request set to https://github.com/Normation/rudder/pull/4806
Actions

Also available in: Atom PDF