[ 
https://issues.apache.org/jira/browse/FLINK-40189?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Taranpreet Kaur updated FLINK-40189:
------------------------------------
    Priority: Minor  (was: Major)

> Found Security Vunerability in IndexGeneratorFactory.java
> ---------------------------------------------------------
>
>                 Key: FLINK-40189
>                 URL: https://issues.apache.org/jira/browse/FLINK-40189
>             Project: Flink
>          Issue Type: Bug
>          Components: Connectors / Opensearch
>            Reporter: Taranpreet Kaur
>            Priority: Minor
>
>   Problem
>   Two regex patterns are vulnerable to catastrophic backtracking 
> (polynomial/exponential runtime):
>   Line 207 — dynamicIndexTimeExtractPattern:
>   Pattern.compile(".*\\\{.+\\|.*\\}.*");
>   Line 209 — dynamicIndexSystemTimeExtractPattern:
>   
> Pattern.compile(".*\\\{\\s*(now\\(\\s*\\)|NOW\\(\\s*\\)|current_timestamp|CURRENT_TIMESTAMP)\\s*\\|.*\\}.*");
>   Why These Are Vulnerable
>   Both patterns use multiple overlapping greedy quantifiers (.*, .+, .*) that 
> can match the same characters. When the regex
>   engine fails to find a match, it backtracks through all possible 
> combinations of how to split the input between these
>   quantifiers.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to