[
https://issues.apache.org/jira/browse/SOLR-15826?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17452618#comment-17452618
]
Jan Høydahl commented on SOLR-15826:
------------------------------------
[Pull Request #439 for main branch|https://github.com/apache/solr/pull/439]
[Pull Request #2622 for
branch_8_11|https://github.com/apache/lucene-solr/pull/2622]
> ResourceLoader should better respect allowed paths
> --------------------------------------------------
>
> Key: SOLR-15826
> URL: https://issues.apache.org/jira/browse/SOLR-15826
> Project: Solr
> Issue Type: Bug
> Security Level: Public(Default Security Level. Issues are Public)
> Reporter: Jan Høydahl
> Assignee: Jan Høydahl
> Priority: Major
> Time Spent: 40m
> Remaining Estimate: 0h
>
> ResourceLoader only returns files relative to instanceDir or resources from
> Classpath, but the check for whether the requested resource is relative to
> instanceDir or not happens after an attempt to check if the file exists. This
> can cause weird bugs, so we should move the check earlier.
--
This message was sent by Atlassian Jira
(v8.20.1#820001)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]