{"id":"GHSA-7rq4-qcpw-74gq","summary":"Formula Injection in Exported Data","details":"### Impact\n\nDatasets exported to file (e.g. CSV / XLS) are not sufficiently sanitized, to neutralize potential formula injection\n\n### Patches\n\n- The issue is addressed in the upcoming 0.8.0 release\n- This fix will also be back-ported to the 0.7.x branch, applied to the 0.7.2 release\n\n### Workarounds\n\nUsers exporting untrusted data should open the files in safe mode (e.g. in Microsoft Excel).\n\n### References\n\n- https://huntr.dev/bounties/e57c36e7-fa39-435f-944a-3a52ee066f73/\n- https://owasp.org/www-community/attacks/CSV_Injection\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [github](http://github.com/inventree/inventree)\n* Email us at [security@inventree.org](mailto:security@inventree.org)\n","modified":"2024-12-08T05:27:25.214106Z","published":"2022-06-17T01:17:22Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-06-17T01:17:22Z"},"references":[{"type":"WEB","url":"https://github.com/inventree/InvenTree/security/advisories/GHSA-7rq4-qcpw-74gq"},{"type":"WEB","url":"https://github.com/inventree/inventree-python"}],"affected":[{"package":{"name":"inventree","ecosystem":"PyPI","purl":"pkg:pypi/inventree"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.2"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9","0.1.0","0.1.1","0.1.2","0.1.3","0.1.4","0.2.4","0.3.1","0.3.2","0.4.4","0.6.0","0.6.1","0.7.0","0.7.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-7rq4-qcpw-74gq/GHSA-7rq4-qcpw-74gq.json"}}],"schema_version":"1.9.0"}