zuul/releasenotes/notes/synchronize-rsh-553872cf5422acf9.yaml
Tristan Cacqueray e4f3f48fef Disable rsh synchronize rsync_opts
This change prevents executor host command execution through a
malicious rsh synchronize rsync_opts.

Fixes bug #2006526

Change-Id: I3cd17ca91410394f164d8ea7cd91a1ea5890f998
2019-09-16 16:25:11 +00:00

7 lines
182 B
YAML

---
security:
- |
The synchronize rsh rsync_opts is now prohibited for security reasons
as it could be used to circumvent executor host command execution
restrictions.