Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • Trac Trac
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Service Desk
    • Milestones
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
  • Wiki
    • Wiki
  • Activity
  • Create a new issue
  • Issue Boards
Collapse sidebar
  • Legacy
  • TracTrac
  • Issues
  • #12269

Closed
Open
Created Jun 11, 2014 by Arturo Filasto@art

Issue H. nettest_to_path Does Not Sanitize the NetTest Name

At 2014-04-23 11:55:49 Arturo Filastò wrote: The path to the Python script containing the test implementation is constructed in an unsafe manner.

Mitigation

Current users can mitigate this risk by only using test decks from trusted sources or manually verifying the test_file parameter of the test deck.

Remediation

Use twisted.python.filepath.FilePath.

This issue was automatically migrated from github issue https://github.com/TheTorProject/ooni-probe/issues/306

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking