7 Star 0 Fork 7

src-openEuler/A-Tune-Collector

加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
文件
该仓库未声明开源许可证文件(LICENSE),使用请关注具体项目描述及其代码上游依赖。
克隆/下载
CVE-2024-24897.patch 1.13 KB
一键复制 编辑 原始数据 按行查看 历史
ZhouPengcheng 提交于 2024-03-12 15:21 +08:00 . fix CVE-2024-24897
From c59e9b4dd509a456fb1fedb50cc7ff9ef7ad55f9 Mon Sep 17 00:00:00 2001
From: zhoupengcheng <zhoupengcheng11@huawei.com>
Date: Mon, 11 Mar 2024 19:05:07 +0800
Subject: [PATCH] preventing possible Shell command injection
---
atune_collector/plugin/monitor/process/sched.py | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/atune_collector/plugin/monitor/process/sched.py b/atune_collector/plugin/monitor/process/sched.py
index 0fadeba..82e6d9f 100644
--- a/atune_collector/plugin/monitor/process/sched.py
+++ b/atune_collector/plugin/monitor/process/sched.py
@@ -68,8 +68,9 @@ class ProcSched(Monitor):
raise err
for app in self.__applications:
- pid = subprocess.getoutput(
- "ps -A | grep {} | awk '{{print $1}}'".format(app)).split()
+ pid = subprocess.getoutput("ps -A")
+ app_processes = [line for line in pid.split('\n') if app in line]
+ pid = [line.split()[0] for line in app_processes]
app_pid_flag = True if pid else False
proc_flag.append(app_pid_flag)
if pid:
--
2.33.0
Loading...
马建仓 AI 助手
尝试更多
代码解读
代码找茬
代码优化
1
https://gitee.com/src-openeuler/A-Tune-Collector.git
git@gitee.com:src-openeuler/A-Tune-Collector.git
src-openeuler
A-Tune-Collector
A-Tune-Collector
master

搜索帮助