Skip to content

Security problem: upload_template () ==> world readable file in the home folder #1341

@indera

Description

@indera

I wast running the upload_template() function from the fabric.contrib.files package and found an unexpected behavior.
If the "destination" parameter points to an invalid path then you end up with a world-readable file in your home folder:

-rw-r--r-- 1 me users 623 Jun 11 12:02 dbdc6b14139b9aaf18cfcd2cb1244440dbf08136

If the file happens to contain a password there is a chance of the somebody reading it.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions