From 5addb2114b2f9765e521a14c317bde8afaee90e3 Mon Sep 17 00:00:00 2001 From: liubo Date: Thu, 11 Nov 2021 12:45:50 +0800 Subject: [PATCH] Fix: fix CVE-2020-28243 Signed-off-by: liubo --- docker/transport/sshconn.py | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/docker/transport/sshconn.py b/docker/transport/sshconn.py index 8e6beb2544..e0cbe0c2a7 100644 --- a/docker/transport/sshconn.py +++ b/docker/transport/sshconn.py @@ -58,9 +58,8 @@ def f(): env.pop('SSL_CERT_FILE', None) self.proc = subprocess.Popen( - ' '.join(args), + args, env=env, - shell=True, stdout=subprocess.PIPE, stdin=subprocess.PIPE, preexec_fn=None if constants.IS_WINDOWS_PLATFORM else preexec_func)