oranenj
Results
33
comments of
oranenj
@andrewwippler @senax I merged the PR. Can you confirm that this is now fixed?
As an addendum, the module does not quote the value of ${home_dir} when it runs the test and rm -rf commands, so there is a potential injection vulnerability. It seems...
Kiling the user's processes is fine and even necessary IMO. It's the rm -rf that is scary. Hmm. You should at least quote the commands properly, run the exec as...