[ 
https://issues.apache.org/jira/browse/YARN-10336?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17175735#comment-17175735
 ] 

Bilwa S T commented on YARN-10336:
----------------------------------

Thanks [~elgoiri] for review.
 # Using singletonMap would return immutableMap and when title is set in 
AppsBlock .it tries to add it to map returned by this method which would throw 
UnsupportedException.

Handled other two comments. Please check

> RM page should throw exception when command injected in RM REST API to get 
> applications
> ---------------------------------------------------------------------------------------
>
>                 Key: YARN-10336
>                 URL: https://issues.apache.org/jira/browse/YARN-10336
>             Project: Hadoop YARN
>          Issue Type: Bug
>            Reporter: Rajshree Mishra
>            Assignee: Bilwa S T
>            Priority: Major
>         Attachments: CommandInject.jpg, RM_UI.jpg, YARN-10336.001.patch, 
> YARN-10336.002.patch, YARN-10336.003.patch, testproof.png
>
>
> Using a web application attacking, we see that injecting commands like 
> ACCEPTED, FAILED and FINISHED to RM REST API does not throw an exception. 
> Refer images.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: yarn-issues-unsubscr...@hadoop.apache.org
For additional commands, e-mail: yarn-issues-h...@hadoop.apache.org

Reply via email to