[ 
https://issues.apache.org/jira/browse/NIFI-16135?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Matt Gilman updated NIFI-16135:
-------------------------------
    Status: Patch Available  (was: In Progress)

> Harden UI handling of URL-derived values used to build nifi-api requests
> ------------------------------------------------------------------------
>
>                 Key: NIFI-16135
>                 URL: https://issues.apache.org/jira/browse/NIFI-16135
>             Project: Apache NiFi
>          Issue Type: Improvement
>          Components: Core UI
>            Reporter: Matt Gilman
>            Assignee: Matt Gilman
>            Priority: Major
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> Some UI views build authenticated nifi-api requests using values taken from 
> the
> browser URL (route parameters and query parameters). These values can be
> influenced by a crafted link opened by an authenticated user, but they are
> currently trusted as-is when constructing the request path.
> This affects:
> * The documentation views, which use URL-supplied component coordinates to
>   request definition and step documentation.
> * The access policy views, which use URL-supplied action/resource values to
>   request policy details.
> * The content viewer, which decides whether to load a query-supplied content
>   reference using a simple string prefix check against the instance URI.
> Because these values are not validated, a crafted link could steer an
> authenticated request to an unintended location, and the content viewer's
> prefix check can be satisfied by a look-alike origin.
> Proposed improvement: treat URL-derived values as untrusted at the point they
> are turned into a request. Validate and encode them so they can only be used 
> as
> their intended path segments, reject anything that isn't (failing closed so no
> request is made), and replace the content viewer's prefix check with a proper
> same-origin comparison. Legitimate values are identifiers and known resource
> names, so expected behavior is unchanged.
> Includes unit test coverage for the new validation and same-origin logic.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to