cloudfoundry-community / bosh-softlayer-pool-server-release

A release repo for the bosh-softlayer-baremetal-server project
Apache License 2.0
0 stars 4 forks source link

Command Injection Vulnerability #43

Open squeedee opened 7 years ago

squeedee commented 7 years ago

This exploit exists in this project. We've highlighted the affected lines

Details in this report

bosh-softlayer-pool-server-release https://github.com/cloudfoundry-community/bosh-softlayer-pool-server-release/blob/master/jobs/vps/templates/pid_utils.sh.erb#L3-L4

maximilien commented 7 years ago

Thanks for the heads up @squeedee

You must have flagged other repos for this. Is there a recommended change for these two lines? Looking at the details and that's not super clear. Thanks for any help.

/cc @zhanggbj

bosh-admin-bot commented 2 years ago

This issue was marked as Stale because it has been open for 21 days without any activity. If no activity takes place in the coming 7 days it will automatically be close. To prevent this from happening remove the Stale label or comment below.