Public bug reported:

Change from the classic sudo to sudo-rs have some negative consequences.

One of them is the missing support for wildcards in commands which can
negatively impact security by forcing administrators to allow much more
command variants than needed (especially when the command has sub-
commands like apt, systemctl etc.)

Two weeks ago the upstream merged pull request allowing a wildcard as
the final argument in command specification:
https://github.com/trifectatechfoundation/sudo-rs/pull/1463

As we are talking about LTS version which can impact security habits of
administrators for years, I think it is very important to include the
support for wildcards. Please consider including it.

** Affects: rust-sudo-rs (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: regression

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2143125

Title:
  Merge from upstream "Add error messages on wildcards and accept a
  'final' wildcard #1463"

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rust-sudo-rs/+bug/2143125/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to