general_hardcoded_tmp only considers /tmp and not other FHS locations
Bug #1473725 reported by
Dave Walker
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Bandit |
Fix Released
|
Undecided
|
Dave Walker |
Bug Description
Currently, only /tmp is considered when looking for hard coded uses of temporary files. Other places that should be part of this test are /var/tmp and /dev/shm.
Maybe also /run, /var/run and /var/lock ?
Changed in bandit: | |
assignee: | nobody → Dave Walker (davewalker) |
status: | New → In Progress |
To post a comment you must log in.
Reviewed: https:/ /review. openstack. org/200882 /git.openstack. org/cgit/ openstack/ bandit/ commit/ ?id=a8325942e41 b0df2489458ee69 80a8e2d39f4501
Committed: https:/
Submitter: Jenkins
Branch: master
commit a8325942e41b0df 2489458ee6980a8 e2d39f4501
Author: Dave Walker (Daviey) <email address hidden>
Date: Sun Jul 12 13:44:33 2015 +0100
Consider other hardcoded tmp paths
Previously general_ hardcoded_ tmp plugin was only testing
for hard-coded usage of "/tmp/", however the same issues
can be present on other FHS locations such as /var/tmp/
and /dev/shm.
This change adds these additional locations for
consideration.
Closes-Bug: #1473725 0a1f30c1c5e41c9 8dd74c13d33
Signed-off-by: Dave Walker (Daviey) <email address hidden>
Change-Id: I76f154134e6cc9