Skip to content

Files

Latest commit

 

History

History
13 lines (7 loc) · 719 Bytes

B612.md

File metadata and controls

13 lines (7 loc) · 719 Bytes

Pattern: Unsafe use of logging.config.listen

Issue: -

Description

The logging.config.listen function provides the ability to listen for external configuration files on a socket server. Because portions of the configuration are passed through eval(), use of this function may open its users to a security risk.

While the function only binds to a socket on localhost, and so does not accept connections from remote machines, there are scenarios where untrusted code could be run under the account of the process which calls listen().

Further Reading