fuweng11 opened a new issue, #12193:
URL: https://github.com/apache/inlong/issues/12193

   ### Description
   
   POST /api/node/testConnection is vulnerable to SSRF. 
DataNodeServiceImpl.testConnection only validates DataNodeRequest.url via 
UrlVerificationUtils.validateUrlNotInternal, but each operator connects using 
its own field, which is never validated.
   
   ### InLong Component
   
   InLong Manager
   
   ### Are you willing to submit PR?
   
   - [x] Yes, I am willing to submit a PR!
   
   ### Code of Conduct
   
   - [x] I agree to follow this project's [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to