tmbdev / tarproc

Detected subprocess popen call with shell equals True BAN-B602
Security
Major
4 years ago4 years old
subprocess call with shell=True identified, security issue.
49        kw["stdout"] = subprocess.PIPE
50    else:
51        kw["stdin"] = subprocess.PIPE
52    proc = subprocess.Popen(cmd, shell=True, **kw)53    proc.gopen_command = cmd
54    stream = proc.stdout if mode[0] == "r" else proc.stdin
55    if "b" not in mode: