rootvector2 opened a new pull request, #793: URL: https://github.com/apache/commons-vfs/pull/793
`SftpStreamProxy.connect` formats the target host into the command it runs on the proxy host, and `HostFileNameParser` only ends a host name at `/ ; ? : @ & = + $ ,`, so everything else in the URI authority reaches the proxy's shell. With a stream proxy configured, resolving `sftp://user@target|id/` runs `nc -q 0 target|id 22` there, and backticks, spaces, newlines, redirections, quotes and a leading `-` pass the same way: OS command injection on the proxy host for an application that resolves a URI whose host it does not choose, the class of CVE-2023-51385 in OpenSSH's `ProxyCommand`. Found while checking where URI components end up in a command line. `connect` now refuses a target host that starts with `-` or holds anything but letters, digits and `- . _ : % [ ]`, before it opens the proxy session. The check sits next to the `String.format` call because that is the one place a URI value is handed to a shell, so it holds for every command format. Host names, IPv4 addresses and bracketed IPv6 literals with a zone id pass as before; the new `SftpStreamProxyTest` records the command an embedded SSH server receives and fails on the current code. - [x] Read the [contribution guidelines](CONTRIBUTING.md) for this project. - [x] Read the [ASF Generative Tooling Guidance](https://www.apache.org/legal/generative-tooling.html) if you use Artificial Intelligence (AI). - [x] I used AI to create any part of, or all of, this pull request. Which AI tool was used to create this pull request, and to what extent did it contribute? Claude Code found the unchecked host in the proxy command and wrote this patch, its test and this description; the test was run against the code with and without the change. - [ ] Run a successful build using the default [Maven](https://maven.apache.org/) goal with `mvn`; that's `mvn` on the command line by itself. The default goal ran on every module with rat, japicmp, javadoc, spotbugs, pmd and checkstyle clean and no test failures, but not error free: the local HTTP provider tests cannot parse the URI built from my machine's host name (`unknown_5e:ad:3d:f7:97:a6`), and they fail the same way without this change. - [x] Write unit tests that match behavioral changes, where the tests fail if the changes to the runtime are not applied. This may not always be possible, but it is a best practice. - [x] Write a pull request description that is detailed enough to understand what the pull request does, how, and why. - [x] Each commit in the pull request should have a meaningful subject line and body. Note that a maintainer may squash commits during the merge process. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
