You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@hbase.apache.org by "Andrew Kyle Purtell (Jira)" <ji...@apache.org> on 2022/06/24 19:12:00 UTC
[jira] [Resolved] (HBASE-13774) DLS, DLR, and replication queue items should not include arbitrary full paths
[ https://issues.apache.org/jira/browse/HBASE-13774?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Andrew Kyle Purtell resolved HBASE-13774.
-----------------------------------------
Resolution: Incomplete
> DLS, DLR, and replication queue items should not include arbitrary full paths
> -----------------------------------------------------------------------------
>
> Key: HBASE-13774
> URL: https://issues.apache.org/jira/browse/HBASE-13774
> Project: HBase
> Issue Type: Bug
> Affects Versions: 1.0.1, 1.1.0, 0.98.12, 1.2.0, 2.0.0
> Reporter: Andrew Kyle Purtell
> Priority: Major
>
> DLS, DLR, and replication queue items should not include arbitrary full pathnames. Audit and fix where we have this. Even with znodes properly secured it seems better to simply record a filename in the queue item and build the full path to the file in storage under a preconfigured root directory with secure permissions.
--
This message was sent by Atlassian Jira
(v8.20.7#820007)