Repository navigation
Commit 3181ad7
committed
cloud-setup-databases: shell-escape values passed to EncryptionCLI
processEncryptionStuff()'s encrypt() built the java EncryptionCLI
command by hand-wrapping each dynamic value in literal double quotes,
then handed the joined string to runCmd(), which runs it through
`subprocess.Popen(..., shell=True)`. Double quotes do not stop the
shell from expanding "$..." inside them, so a password like
`pa$sword` is silently truncated to `pa` before it ever reaches
EncryptionCLI, and the wrong value gets encrypted into db.properties.
Use shlex.quote() instead of manual double-quote wrapping for the jar
path, the value being encrypted, and the management server secret
key. shlex.quote() produces shell-safe quoting for arbitrary values,
including but not limited to '$'.
Verified with a standalone reproduction that shells out the same way
runCmd() does: with the old double-quote wrapping, a password of
`pa$sword` arrives at the child process as `pa`; with shlex.quote(),
it arrives intact as `pa$sword`.
Fixes: #14186
Signed-off-by: SiddharthSanch <111047247+SiddharthSanch@users.noreply.github.com>1 parent ac8d69c commit 3181ad7
1 file changed
Lines changed: 8 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| 24 | + | |
24 | 25 | | |
25 | 26 | | |
26 | 27 | | |
| |||
418 | 419 | | |
419 | 420 | | |
420 | 421 | | |
421 | | - | |
422 | | - | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
423 | 429 | | |
424 | 430 | | |
425 | 431 | | |
| |||
0 commit comments