Skip to content

remove shell=true#63

Open
mohmamedali wants to merge 1 commit intosonic-net:masterfrom
mohmamedali:ZTPlib_sec
Open

remove shell=true#63
mohmamedali wants to merge 1 commit intosonic-net:masterfrom
mohmamedali:ZTPlib_sec

Conversation

@mohmamedali
Copy link

What I did
"subprocess.popen" with shell=true uses shell invocation to execute command which is dangerous. without a static string that can lead to command injection.

How I did it
change run command function to run executables without shell invocation

How to verify it
pass UT

@mssonicbld
Copy link

/azp run

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants