Merge pull request #529 from 418sec/7-other-sebhildebrandt/systeminformation

Security Fix for Improper Access Control - Generic (CWE-284) - huntr.dev
This commit is contained in:
Sebastian Hildebrandt 2021-05-04 15:33:34 +02:00 committed by GitHub
commit bb010817e8
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -159,7 +159,7 @@ function dockerImagesInspect(imageID, payload) {
process.nextTick(() => {
imageID = imageID || '';
if (typeof imageID !== 'string') {
resolve();
return resolve();
}
const imageIDSanitized = (util.isPrototypePolluted() ? '' : util.sanitizeShellString(imageID, true)).trim();
if (imageIDSanitized) {
@ -307,7 +307,7 @@ function dockerContainerInspect(containerID, payload) {
process.nextTick(() => {
containerID = containerID || '';
if (typeof containerID !== 'string') {
resolve();
return resolve();
}
const containerIdSanitized = (util.isPrototypePolluted() ? '' : util.sanitizeShellString(containerID, true)).trim();
if (containerIdSanitized) {
@ -601,7 +601,7 @@ function dockerContainerProcesses(containerID, callback) {
process.nextTick(() => {
containerID = containerID || '';
if (typeof containerID !== 'string') {
resolve(result);
return resolve(result);
}
const containerIdSanitized = (util.isPrototypePolluted() ? '' : util.sanitizeShellString(containerID, true)).trim();