6 ms·
I had the same reaction as you... it looks like the vulnerability is coming from git, that's a very dangerous behavior.
by kirby88 5y ago
I had the same reaction as you... it looks like the vulnerability is coming from git, that's a very dangerous behavior.
- xucheng 5y agoI think I understand why this is happening. This is not an issue that argument parsing in git goes wrong. But instead, the `--upload-pack=` instructs git to run certain command in the remote server. In my above example (`system "git", "ls-remote", "--upload-pack=$(whoami)", "HEAD"`), HEAD is interpreted as a local file based git server. As such, the command is executed in the same machine.
- kirby88 5y agoI don't think so, you just forgot to add the remote server address. If you run `system "git", "ls-remote", " --upload-pack=$(touch hello) git@github.com:torvalds/linux.git", "HEAD"` it will fetch the remote server but still create the file on the local machine.
- xucheng 5y agoIn your example, `HEAD` is the server address, which is interpreted as a local file. `$(touch hello) git@github.com:torvalds/linux.git` is the command to be run in the remote (locally in this case). It will not connect to the server in GitHub. P.S. it seems that you have an extra space before `--upload-pack`.