Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[sonic-platform-modules] subprocess with no shell #21481

Open
mohmamedali opened this issue Jan 20, 2025 · 2 comments
Open

[sonic-platform-modules] subprocess with no shell #21481

mohmamedali opened this issue Jan 20, 2025 · 2 comments
Assignees
Labels
Triaged this issue has been triaged

Comments

@mohmamedali
Copy link

sonic platform scripts use many mechanisms to invoke an external executable. However, doing so may present a security issue if appropriate care is not taken to sanitize any user provided or variable input. If possible, we have to ensure that all external commands called from the program are statically created. currently some vendor started to use safe mechanisms but others still use old ways. is there any plan to unify the development approach?.

@vdahiya12
Copy link
Contributor

@qiluo-msft to check if this is still the case

@vdahiya12 vdahiya12 added the Triaged this issue has been triaged label Jan 29, 2025
@qiluo-msft
Copy link
Collaborator

@mohmamedali Is should be completed. Do you see any remaining problematic use cases?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Triaged this issue has been triaged
Projects
None yet
Development

No branches or pull requests

4 participants