bamaer opened a new pull request, #8316:
URL: https://github.com/apache/hop/pull/8316

   … fixes #8311
   
   GPG.execGnuPG() built a single command string and ran it through a shell 
(/bin/sh -c on POSIX, Runtime.exec(String) on Windows). Callers concatenated 
filenames, key IDs and the passphrase into that string wrapped in double 
quotes, which do not prevent shell expansion. Filenames come from a directory 
scan, so their content was interpreted rather than passed to GnuPG literally.
   
   execGnuPG now takes a List<String> and uses ProcessBuilder directly, with no 
shell involved. The ten call sites in the same file build argument lists.
   
   Also on the same code path: the passphrase moves from the command line, 
where it was readable through the process table, to stdin. GnuPG 2.1 and later 
ignore a passphrase given that way unless the loopback pinentry is requested, 
so that option is now passed as well - without it, decrypting with a passphrase 
and the PGP decrypt stream transform have been failing on any current GnuPG.
   
   Tests: an argument-recording harness asserts what GnuPG actually receives 
for every converted method, including that a command substitution in a filename 
or key ID is never executed. Six integration tests cover folder scanning with 
hostile filenames, binary encrypt, detached verify, decrypt with a passphrase, 
the PGP stream transforms, and a command-injection proof. Against the previous 
implementation 16 of these 25 tests fail.
   
   **Please** add a meaningful description for your change here
   
   ------------------------
   
   Thank you for your contribution! Follow this checklist to help us 
incorporate your contribution quickly and easily:
   - [x] Run `mvn clean install apache-rat:check` to make sure basic checks 
pass. A more thorough check will be performed on your pull request 
automatically.
   - [x] If you have a group of commits related to the same change, please 
squash your commits into one and force push your branch using `git rebase -i`.
   - [x] Mention the appropriate issue in your description (for example: 
`addresses #123`), if applicable.
   
   To make clear that you license your contribution under the [Apache License 
Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0)
   you have to acknowledge this by using the following check-box.
   
   - [x] I hereby declare this contribution to be licensed under the [Apache 
License Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0)
   - [ ] In any other case, please file an [Apache Individual Contributor 
License Agreement](https://www.apache.org/licenses/icla.pdf).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to