Version 3.5.30 has calls to shell_exec
-
Hi
Version 3.5.30 has calls to shell_exec depends on monolog (composer), but this version has two calls to shell_exec(), so it’s raising alarms with our PHP malware scanners.
- monolog/src/Monolog/Processor/GitProcessor.php
- monolog/src/Monolog/Processor/MercurialProcessor.php
Do you really need the “monolog” package, and its calls to shell_exec() ?
We’ve put in a temporary patch at our end for now, but if you need shell_exec() in your plugin, we’ll need to put in long-term file exclusions in our PHP malware scanner rules (not ideal).
Paul
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
You must be logged in to reply to this topic.