IGNITE-28743 Block remote HTTP/HTTPS/FTP URLs in resolveSpringUrl#13221
Open
animovscw wants to merge 3 commits into
Open
IGNITE-28743 Block remote HTTP/HTTPS/FTP URLs in resolveSpringUrl#13221animovscw wants to merge 3 commits into
animovscw wants to merge 3 commits into
Conversation
Contributor
TCBot Test Analysis
Possible Blockers (6)
New Tests (5)
|
zstan
reviewed
Jun 18, 2026
| * FTP is always blocked regardless of this property due to MITM risk. | ||
| */ | ||
| @SystemProperty(value = "Allow remote HTTP/HTTPS URLs when loading Spring XML configuration") | ||
| public static final String IGNITE_ALLOW_REMOTE_SPRING_CFG_URL = "ignite.spring.cfg.allowRemoteUrl"; |
Contributor
There was a problem hiding this comment.
seems also need to cover this flag usage in tests ?
zstan
reviewed
Jun 18, 2026
| */ | ||
| @Test | ||
| public void testFtpCfgUrlIsAlwaysBlocked() { | ||
| final String url = CFG_URL_PREFIX + "ftp://attacker.example.com/evil.xml"; |
Contributor
There was a problem hiding this comment.
Lets reduce tests a bit ? Use for loop with List.of("ftp", "https", "http") and "ftps" ?
Contributor
|
Also seems all fails need to be fixed ? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
… prevent RCE via JDBC cfg://
Thank you for submitting the pull request to the Apache Ignite.
In order to streamline the review of the contribution
we ask you to ensure the following steps have been taken:
The Contribution Checklist
The description explains WHAT and WHY was made instead of HOW.
The following pattern must be used:
IGNITE-XXXX Change summarywhereXXXX- number of JIRA issue.(see the Maintainers list)
the
green visaattached to the JIRA ticket (see tabPR Checkat TC.Bot - Instance 1 or TC.Bot - Instance 2)Notes
If you need any help, please email dev@ignite.apache.org or ask anу advice on http://asf.slack.com #ignite channel.