diff options
author | Jo-Philipp Wich <jo@mein.io> | 2021-10-08 20:22:58 +0200 |
---|---|---|
committer | Jo-Philipp Wich <jo@mein.io> | 2021-10-08 20:27:13 +0200 |
commit | 44445a8097d05dbcc807c95c5b2c016f1a49a350 (patch) | |
tree | b5c3f4aff6f62b8b34dc635e08f5980cf29f3c3e /applications/luci-app-mwan3/po/ja | |
parent | 21af8a34fdcfd78dc125c7cf9a6372925c074477 (diff) |
luci-proto-wireguard: fix potential shell injection vulnerabilities
The `luci.wireguard.generateQrCode` UBUS method allows injecting
arbitrary shell code by not sanitizing the `privkey` and `allowed_ips`
arguments before concatenating them into shell command expressions.
Signed-off-by: Jo-Philipp Wich <jo@mein.io>
Diffstat (limited to 'applications/luci-app-mwan3/po/ja')
0 files changed, 0 insertions, 0 deletions