ppkarwasz commented on issue #3794:
URL:
https://github.com/apache/logging-log4j2/issues/3794#issuecomment-5831447532
Two more points for this issue:
1. **Non-HTTP schemes in the one-argument `createConnection(URL)`.**
Only `http` and `https` go through the four-argument overload that checks
`log4j2.configurationAllowedProtocols`;
any other scheme (e.g. `ftp:`) goes straight to `url.openConnection()`.
The documentation currently overstates the allowlist:
- `properties-transport-security.adoc` says the property applies to "any
kind of configuration source"
and that `_none` "completely prevent[s] accessing the configuration via
the Java `URL` class";
- the `Log4jEntityResolver` Javadoc says external entities are "subject
to the same restrictions
(e.g. the `log4j2.Configuration.allowedProtocols` property)".
Either the check should apply to all schemes, or the documentation should
say which paths it covers.
2. **Nested `jar:` URLs.** Both overloads check only the outer scheme,
so `jar:http://host/config.jar!/log4j2.xml` passes the default allowlist
(`jar` is allowed)
while `JarURLConnection` fetches the inner `http:` URL.
The inner URL of a `jar:` URL should be checked against the allowlist as
well.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]