Pattern: Unsafe use of logging.config.listen
Issue: -
The logging.config.listen
function provides the ability to listen for external configuration files on a socket server. Because portions of the configuration are passed through eval()
, use of this function may open its users to a security risk.
While the function only binds to a socket on localhost, and so does not accept connections from remote machines, there are scenarios where untrusted code could be run under the account of the process which calls listen()
.