Jesse Glick commented on Improvement JENKINS-26838

Does not suffice. First of all, it assumes the child exists, which many legitimate use cases cannot assume. Second, it is buggy:

$ mkdir -p /tmp/basedir && touch /tmp/basedir-attacked && jrunscript -classpath ~/.m2/repository/commons-io/commons-io/2.4/commons-io-2.4.jar -e 'println(org.apache.commons.io.FileUtils.directoryContains(new java.io.File("/tmp/basedir"), new java.io.File("/tmp/basedir-attacked")))'
true
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira

--
You received this message because you are subscribed to the Google Groups "Jenkins Issues" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to