Repository: hadoop Updated Branches: refs/heads/trunk 0f701f433 -> 85422bb7c
HADOOP-13299. JMXJsonServlet is vulnerable to TRACE. (Haibo Chen via kasha) Project: http://git-wip-us.apache.org/repos/asf/hadoop/repo Commit: http://git-wip-us.apache.org/repos/asf/hadoop/commit/85422bb7 Tree: http://git-wip-us.apache.org/repos/asf/hadoop/tree/85422bb7 Diff: http://git-wip-us.apache.org/repos/asf/hadoop/diff/85422bb7 Branch: refs/heads/trunk Commit: 85422bb7c5d3e70a49f620ba1c8800e0ba4b64f2 Parents: 0f701f4 Author: Karthik Kambatla <[email protected]> Authored: Tue Aug 9 13:42:25 2016 -0700 Committer: Karthik Kambatla <[email protected]> Committed: Tue Aug 9 13:42:32 2016 -0700 ---------------------------------------------------------------------- .../java/org/apache/hadoop/jmx/JMXJsonServlet.java | 11 ++++++++++- .../java/org/apache/hadoop/jmx/TestJMXJsonServlet.java | 13 +++++++++++++ 2 files changed, 23 insertions(+), 1 deletion(-) ---------------------------------------------------------------------- http://git-wip-us.apache.org/repos/asf/hadoop/blob/85422bb7/hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/jmx/JMXJsonServlet.java ---------------------------------------------------------------------- diff --git a/hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/jmx/JMXJsonServlet.java b/hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/jmx/JMXJsonServlet.java index 9ade62f..b6ec7bc 100644 --- a/hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/jmx/JMXJsonServlet.java +++ b/hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/jmx/JMXJsonServlet.java @@ -147,7 +147,16 @@ public class JMXJsonServlet extends HttpServlet { return HttpServer2.isInstrumentationAccessAllowed(getServletContext(), request, response); } - + + /** + * Disable TRACE method to avoid TRACE vulnerability. + */ + @Override + protected void doTrace(HttpServletRequest req, HttpServletResponse resp) + throws ServletException, IOException { + resp.sendError(HttpServletResponse.SC_METHOD_NOT_ALLOWED); + } + /** * Process a GET request for the specified resource. * http://git-wip-us.apache.org/repos/asf/hadoop/blob/85422bb7/hadoop-common-project/hadoop-common/src/test/java/org/apache/hadoop/jmx/TestJMXJsonServlet.java ---------------------------------------------------------------------- diff --git a/hadoop-common-project/hadoop-common/src/test/java/org/apache/hadoop/jmx/TestJMXJsonServlet.java b/hadoop-common-project/hadoop-common/src/test/java/org/apache/hadoop/jmx/TestJMXJsonServlet.java index cf7014d..035090e 100644 --- a/hadoop-common-project/hadoop-common/src/test/java/org/apache/hadoop/jmx/TestJMXJsonServlet.java +++ b/hadoop-common-project/hadoop-common/src/test/java/org/apache/hadoop/jmx/TestJMXJsonServlet.java @@ -24,6 +24,8 @@ import org.junit.AfterClass; import org.junit.BeforeClass; import org.junit.Test; +import javax.servlet.http.HttpServletResponse; +import java.io.IOException; import java.net.HttpURLConnection; import java.net.URL; import java.util.regex.Matcher; @@ -81,4 +83,15 @@ public class TestJMXJsonServlet extends HttpServerFunctionalTest { assertEquals("GET", conn.getHeaderField(ACCESS_CONTROL_ALLOW_METHODS)); assertNotNull(conn.getHeaderField(ACCESS_CONTROL_ALLOW_ORIGIN)); } + + @Test + public void testTraceRequest() throws IOException { + URL url = new URL(baseUrl, "/jmx"); + HttpURLConnection conn = (HttpURLConnection) url.openConnection(); + conn.setRequestMethod("TRACE"); + + assertEquals("Unexpected response code", + HttpServletResponse.SC_METHOD_NOT_ALLOWED, conn.getResponseCode()); + } + } --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
