[jira] [Commented] (SPARK-45273) Http header Attack【HttpSecurityFilter】

2023-09-22 Thread Sean R. Owen (Jira)


[ 
https://issues.apache.org/jira/browse/SPARK-45273?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17768144#comment-17768144
 ] 

Sean R. Owen commented on SPARK-45273:
--

Yep we typically evaluate security reports on priv...@spark.apache.org first, 
not here

> Http header Attack【HttpSecurityFilter】
> --
>
> Key: SPARK-45273
> URL: https://issues.apache.org/jira/browse/SPARK-45273
> Project: Spark
>  Issue Type: Bug
>  Components: Spark Core
>Affects Versions: 3.5.0
>Reporter: chenyu
>Priority: Major
>
> There is an HTTP host header attack vulnerability in the target URL



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

-
To unsubscribe, e-mail: issues-unsubscr...@spark.apache.org
For additional commands, e-mail: issues-h...@spark.apache.org



[jira] [Commented] (SPARK-45273) Http header Attack【HttpSecurityFilter】

2023-09-22 Thread Jira


[ 
https://issues.apache.org/jira/browse/SPARK-45273?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17768140#comment-17768140
 ] 

Bjørn Jørgensen commented on SPARK-45273:
-

Hi, [~chenyu-opensource] can you take this on mail to secur...@spark.apache.org 
CC [~srowen]

> Http header Attack【HttpSecurityFilter】
> --
>
> Key: SPARK-45273
> URL: https://issues.apache.org/jira/browse/SPARK-45273
> Project: Spark
>  Issue Type: Bug
>  Components: Spark Core
>Affects Versions: 3.5.0
>Reporter: chenyu
>Priority: Major
>
> There is an HTTP host header attack vulnerability in the target URL



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

-
To unsubscribe, e-mail: issues-unsubscr...@spark.apache.org
For additional commands, e-mail: issues-h...@spark.apache.org