ppkarwasz commented on issue #3794:
URL: 
https://github.com/apache/logging-log4j2/issues/3794#issuecomment-5831447532

   Two more points for this issue:
   
   1. **Non-HTTP schemes in the one-argument `createConnection(URL)`.**
      Only `http` and `https` go through the four-argument overload that checks 
`log4j2.configurationAllowedProtocols`;
      any other scheme (e.g. `ftp:`) goes straight to `url.openConnection()`.
      The documentation currently overstates the allowlist:
      - `properties-transport-security.adoc` says the property applies to "any 
kind of configuration source"
        and that `_none` "completely prevent[s] accessing the configuration via 
the Java `URL` class";
      - the `Log4jEntityResolver` Javadoc says external entities are "subject 
to the same restrictions
        (e.g. the `log4j2.Configuration.allowedProtocols` property)".
   
      Either the check should apply to all schemes, or the documentation should 
say which paths it covers.
   
   2. **Nested `jar:` URLs.** Both overloads check only the outer scheme,
      so `jar:http://host/config.jar!/log4j2.xml` passes the default allowlist 
(`jar` is allowed)
      while `JarURLConnection` fetches the inner `http:` URL.
      The inner URL of a `jar:` URL should be checked against the allowlist as 
well.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to