You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@flink.apache.org by "nate (Jira)" <ji...@apache.org> on 2021/01/11 02:16:00 UTC

[jira] [Created] (FLINK-20916) Typo in test for CVE-2020-17519

nate created FLINK-20916:
----------------------------

             Summary: Typo in test for CVE-2020-17519
                 Key: FLINK-20916
                 URL: https://issues.apache.org/jira/browse/FLINK-20916
             Project: Flink
          Issue Type: Bug
          Components: Runtime / REST
            Reporter: nate


 

The testGetJobManagerCustomLogsExistingButForbiddenFileWithObfuscatedPath test for CVE-2020-17519 Path Traversal has a typo that causes it to inaccurately test for the vuln. 

It uses for format string "..%%252%s" when it should be "..%%252f%s".



--
This message was sent by Atlassian Jira
(v8.3.4#803005)