Skip to content

IGNITE-28743 Block remote HTTP/HTTPS/FTP URLs in resolveSpringUrl prevent RCE via JDBC cfg://#13382

Open
animovscw wants to merge 21 commits into
apache:masterfrom
animovscw:ignite-28743-2
Open

IGNITE-28743 Block remote HTTP/HTTPS/FTP URLs in resolveSpringUrl prevent RCE via JDBC cfg://#13382
animovscw wants to merge 21 commits into
apache:masterfrom
animovscw:ignite-28743-2

Conversation

@animovscw

Copy link
Copy Markdown
Contributor

Thank you for submitting the pull request to the Apache Ignite.

In order to streamline the review of the contribution
we ask you to ensure the following steps have been taken:

The Contribution Checklist

  • There is a single JIRA ticket related to the pull request.
  • The web-link to the pull request is attached to the JIRA ticket.
  • The JIRA ticket has the Patch Available state.
  • The pull request body describes changes that have been made.
    The description explains WHAT and WHY was made instead of HOW.
  • The pull request title is treated as the final commit message.
    The following pattern must be used: IGNITE-XXXX Change summary where XXXX - number of JIRA issue.
  • A reviewer has been mentioned through the JIRA comments
    (see the Maintainers list)
  • The pull request has been checked by the Teamcity Bot and
    the green visa attached to the JIRA ticket (see tab PR Check at TC.Bot - Instance 1 or TC.Bot - Instance 2)

Notes

If you need any help, please email dev@ignite.apache.org or ask anу advice on http://asf.slack.com #ignite channel.

Comment thread modules/core/src/main/java/org/apache/ignite/internal/util/IgniteUtils.java Outdated
Comment thread modules/core/src/main/java/org/apache/ignite/internal/util/IgniteUtils.java Outdated
Comment thread modules/core/src/main/java/org/apache/ignite/internal/util/IgniteUtils.java Outdated
Comment thread modules/core/src/main/java/org/apache/ignite/internal/util/IgniteUtils.java Outdated
Comment thread modules/core/src/main/java/org/apache/ignite/internal/util/IgniteUtils.java Outdated
// the scheme can be inspected, which would otherwise bypass this check.
String lowerPath = springCfgPath.toLowerCase(Locale.ROOT);

for (String blockedScheme : ALWAYS_BLOCKED_CFG_SCHEMES) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why we have two check places ? here and a bit lower ? i comment this check and only one test failed due to different error message

animovscw and others added 6 commits July 24, 2026 22:41
…iteUtils.java

Co-authored-by: Evgeniy Stanilovskiy <stanilovsky@gmail.com>
…iteUtils.java

Co-authored-by: Evgeniy Stanilovskiy <stanilovsky@gmail.com>
…iteUtils.java

Co-authored-by: Evgeniy Stanilovskiy <stanilovsky@gmail.com>
…iteUtils.java

Co-authored-by: Evgeniy Stanilovskiy <stanilovsky@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants