Denial of the responsibility for security vulnerabilities in the netbox-application #4303

Closed
opened 2025-12-29 18:34:31 +01:00 by adam · 1 comment
Owner

Originally created by @x13x13x on GitHub (Nov 25, 2020).

Dear Netbox team,

as I read the issues,
Issue #1174
Issue #2788
I just needed to create this Issue for the information of you and everybody else reading this post.

Security vulnerabilities like the ones mentioned in this issues are definetly your responsibility and also a problem of your application. If you use outdated Third-Party-Libraries like jQuery-UI and they have vulnerabilities these vulnerabilities are also your vulnerabilities, because it is in your responsibility which libraries and software you use in your application. And it is also your responsibility to use components WITHOUT vulnerabilities if you want to create a secure piece of software.

Also a CSV-Injection vulnerabilities is not a Excel-Problem. It is a known vulnerabilities which needs to be prevented by the developers of an application if they want to offer a CSV export. If you dont want to prevent that vulnerability in your application just dont use it or state that you deliberately do not fix vulnerabilities in your application!
Just to clarify, if the vulnerability CSV-Injection exists in your application it is in fact a netbox-issue because you dont prevent it.

thank you

Originally created by @x13x13x on GitHub (Nov 25, 2020). Dear Netbox team, as I read the issues, [Issue #1174](https://github.com/netbox-community/netbox/issues/1174) [Issue #2788](https://github.com/netbox-community/netbox/issues/2788) I just needed to create this Issue for the information of you and everybody else reading this post. Security vulnerabilities like the ones mentioned in this issues are definetly your responsibility and also a problem of your application. If you use outdated Third-Party-Libraries like jQuery-UI and they have vulnerabilities these vulnerabilities are also your vulnerabilities, because it is in your responsibility which libraries and software you use in your application. And it is also your responsibility to use components WITHOUT vulnerabilities if you want to create a secure piece of software. Also a CSV-Injection vulnerabilities is not a Excel-Problem. It is a known vulnerabilities which needs to be prevented by the developers of an application if they want to offer a CSV export. If you dont want to prevent that vulnerability in your application just dont use it or state that you deliberately do not fix vulnerabilities in your application! Just to clarify, if the vulnerability CSV-Injection exists in your application it is in fact a netbox-issue because you dont prevent it. thank you
adam closed this issue 2025-12-29 18:34:32 +01:00
Author
Owner

@jeremystretch commented on GitHub (Nov 25, 2020):

This issue is has been closed as it does not conform to one of the provided templates as required by the contributing guide. If you'd like to request that your issue be re-opened, please first update the content so that it matches the appropriate template (this may require rewriting your issue entirely).

@jeremystretch commented on GitHub (Nov 25, 2020): This issue is has been closed as it does not conform to one of the [provided templates](https://github.com/netbox-community/netbox/issues/new/choose) as required by the [contributing guide](https://github.com/netbox-community/netbox/blob/master/CONTRIBUTING.md). If you'd like to request that your issue be re-opened, please first update the content so that it matches the appropriate template (this may require rewriting your issue entirely).
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/netbox#4303