Commit 0e927c2
committed
fix(reporting): neutralize spreadsheet formulas in CSV export
encoding/csv stops a value from breaking out of its cell, but it does not
stop a spreadsheet from evaluating that cell. Widening the schema pulled
response-derived data into the file: extracted-results comes straight from
OutputExtracts, so a target chooses exactly what lands in that column. A
value such as =cmd|'/C calc'!A0 was written verbatim and executed when the
export was opened (CWE-1236).
formatRow now routes every string column through neutralizeFormula, which
prefixes a single apostrophe to values starting with = + - @ TAB or CR.
Values that parse as a number are left alone so cvss-score and port stay
numeric and sortable. Multi-value columns (extracted-results, reference)
are neutralized per element rather than only at the head of the cell,
because consumers split those cells back apart.
The transformation is reversible: the original value is the cell with at
most one leading apostrophe removed.
Tests: TestCSVExporterNeutralizesSpreadsheetFormulas asserts DDE,
HYPERLINK, @ and +/- payloads are neutralized across template-id,
template-name, description, host, matcher-name, curl-command,
extracted-results and reference while safe values and cvss-score are
untouched; TestNeutralizeFormula table-tests the helper, including the
numeric, leading-space and non-ASCII cases.
Signed-off-by: Devam Shah <devamshah91@gmail.com>1 parent 8c0f656 commit 0e927c2
2 files changed
Lines changed: 163 additions & 17 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
105 | 105 | | |
106 | 106 | | |
107 | 107 | | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
108 | 147 | | |
109 | 148 | | |
110 | 149 | | |
111 | 150 | | |
112 | | - | |
113 | | - | |
114 | | - | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
115 | 156 | | |
116 | 157 | | |
117 | 158 | | |
| |||
128 | 169 | | |
129 | 170 | | |
130 | 171 | | |
131 | | - | |
| 172 | + | |
132 | 173 | | |
133 | 174 | | |
134 | 175 | | |
135 | | - | |
136 | | - | |
137 | | - | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
138 | 179 | | |
139 | | - | |
140 | | - | |
141 | | - | |
142 | | - | |
143 | | - | |
144 | | - | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
145 | 186 | | |
146 | 187 | | |
147 | 188 | | |
148 | 189 | | |
149 | | - | |
| 190 | + | |
150 | 191 | | |
151 | 192 | | |
152 | | - | |
| 193 | + | |
153 | 194 | | |
154 | | - | |
| 195 | + | |
155 | 196 | | |
156 | | - | |
| 197 | + | |
157 | 198 | | |
158 | 199 | | |
159 | 200 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
271 | 271 | | |
272 | 272 | | |
273 | 273 | | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
| 324 | + | |
| 325 | + | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
| 365 | + | |
| 366 | + | |
| 367 | + | |
| 368 | + | |
| 369 | + | |
| 370 | + | |
| 371 | + | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
0 commit comments