A checkout path containing shell syntax ($(), quotes) could otherwise inject code into /usr/local/bin/clusev, which runs as root via 'sudo clusev update'. Render the path through printf %q into an unquoted assignment; add a test that a hostile path does not execute injected code. |
||
|---|---|---|
| .. | ||
| Feature | ||
| Unit | ||
| scripts | ||
| TestCase.php | ||