Issue 2151 🛂 do not give users a root shell by executing arbitrary shell commands by 'vim' #2152
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This PR fixes #2151 by by removing 'sudo' aliases because bash-it should not be the business of mucking about with sudo at all.
Initial purpose of this PR has changed and has been:
Use
sudoedit
instead ofsudo vim
which is a big security issue because users can get a root shell by executing arbitrary shell commands byvim
!Motivation and Context
Nobody wants users to allow to become root just because they can edit any file (which would also make them root by manipulating the "right" with the "right" commands).
Issue #2151 will be fixed by this PR.
How Has This Been Tested?
I use
sudoedit
instead ofsudo vim
for some decades on different linux distributions and also on MacOS 😁Types of changes
Checklist:
clean_files.txt
and formatted it usinglint_clean_files.sh
. - no files added