[Security/Low] D365 OData $filter built via unescaped string interpolation
Open-source Excel-native EPM and consolidation for SAP & Dynamics
Brought to you by:
konsolid-at
Originally created by: pyy3
Severity: Low–Medium · Type: security / robustness
The D365 incremental sync builds the OData $filter by interpolating the cursor value directly into the query string with no quoting/escaping or type validation.
source-d365-fno/source_d365_fno/streams.py (~line 157):
cursor_value = (stream_state or {}).get(self.cursor_field)
if cursor_value and params:
params["$filter"] = f"{self.cursor_field} ge {cursor_value}"
The cursor originates from D365-returned data / persisted Airbyte state rather than direct end-user input, so this is primarily a robustness + tampering concern rather than open injection:
'...') and would otherwise produce a malformed filter.cursor_value type before use (expect ISO datetime / known type); reject otherwise.
Ticket changed by: pyy3
Originally posted by: pyy3
Fixed in [#34] (merged to
main).Related
Tickets:
#34