Skip to content

Conversation

NicolasToussaint
Copy link
Member

Description

Fixes situation where attackers could run arbitrary system-level OS commands on the Fossology server host.

The vulnerabilities were detected with a Checkmarx scan.

Changes

Introduced the use of the php function escapeshellarg where necessary

as untrusted string may contain malicious system-level commands
engineered by an attacker

Signed-off-by: Toussaint Nicolas <[email protected]>
Copy link
Member

@shaheemazmalmmd shaheemazmalmmd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code looks good.

@NicolasToussaint
Copy link
Member Author

Thank you Shaheem

@NicolasToussaint NicolasToussaint deleted the fix/orange-opensource/security/fix-command-injection branch January 2, 2023 11:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants