cgivre opened a new pull request, #3090:
URL: https://github.com/apache/drill/pull/3090

   Potential fix for 
[https://github.com/apache/drill/security/code-scanning/43](https://github.com/apache/drill/security/code-scanning/43)
   
   To fix this without changing intended behavior, enforce explicit hostname 
validation against the set of known Drillbit endpoints before 
constructing/sending the HTTP request.
   
   Best approach:
   - In `DrillRoot.shutdownDrillbitByName(...)`, validate `hostname` using 
`work.getContext().getAvailableBits()` and only proceed if there is an exact 
match.
   - Reject invalid hostnames with an exception (consistent with existing 
exception-driven flow).
   - Keep using `WebUtils.getDrillbitURL(...)` and `doHTTPRequest(...)` after 
validation so functionality remains unchanged for valid Drillbit hosts.
   
   This is a minimal, targeted fix in:
   - 
`exec/java-exec/src/main/java/org/apache/drill/exec/server/rest/DrillRoot.java`
     - Method: `shutdownDrillbitByName(...)`
     - Add a pre-check for null/empty and allowlist membership.
   
   No changes are required in `WebUtils.java` for this fix.
   
   
   _Suggested fixes powered by Copilot Autofix. Review carefully before 
merging._
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to