mirror of https://github.com/ansible/ansible.git
Rename the type filter to type_debug
Because we add the names of all filters to the callable whitelist used by safe_eval, adding a filter named type makes it so code calling "type()" gets eval'd. We can't think of a way to exploit this but it's sufficiently sketchy that we're renaming it in case someone smarter than us can think of a problem.pull/20163/head
parent
4cdb266dac
commit
eeebd51f21
Loading…
Reference in New Issue