Skip to content

asterisk: fix vulnerabilities associated with "echo -e"

Erik Karlsson requested to merge erik-asterisk-echo-vulnerability into devel

If multiple arguments are allowed to be passed to echo, it is possible to inject newlines using something like '-e aaa\nbbb\nccc" in UCI.

Also fix missing quotation and missing escape_sed

Merge request reports