T03 · Remote Payload Retrieval and Execution
- Location
templates/install_nodejs.sh:9- Finding
Unverified Remote Scripts Are Executed Directly by a Shell
- Content
View full analysis
- Remediation
View remediation
&2; exit 1 ;; esac tmp_script="$(mktemp)" trap 'rm -f "$tmp_script"' EXIT curl --fail --silent --show-error --location \ "https://deb.nodesource.com/setup_${NODE_VERSION}.x" \ --output "$tmp_script" echo " $tmp_script" | sha256sum --check - bash "$tmp_script" ``` The digest must be obtained through a trusted release process and updated only after reviewing the new script. ]]>
