A checkout path containing shell syntax ($(), quotes) could otherwise inject code into /usr/local/bin/clusev, which runs as root via 'sudo clusev update'. Render the path through printf %q into an unquoted assignment; add a test that a hostile path does not execute injected code. |
||
|---|---|---|
| .. | ||
| caddy | ||
| clusev | ||
| motd | ||
| nginx | ||
| php | ||
| restart-sentinel | ||
| supervisor | ||
| entrypoint.sh | ||