Bugzilla – Bug 1143668
AUDIT-FIND: obs-service-renderspec: path traversal
Last modified: 2020-11-24 15:47:07 UTC
--output-name can specify the full path, not just files in the build root
That issue still exists, but is minor IMHO. For that to work the output parameter would have to pretty obviously evil, so that everyone that has a look notices it. Still a good hardening to add
also trackin in github as https://github.com/openSUSE/obs-service-renderspec/issues/16