devtron icon indicating copy to clipboard operation
devtron copied to clipboard

Bug: Passwords are not sanitised

Open mhaddon opened this issue 4 years ago • 0 comments

Passwords for docker and git do not seem to be sanitised. That means passwords with a # in them are treated as a comment, and passwords with a & in them are processed in a background thread.

Meaning if your dockerhub password is "&rm -rf / --no-preserve root", you might have a fun time.

AB#374

mhaddon avatar Jul 22 '21 19:07 mhaddon