You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@hbase.apache.org by "Duo Zhang (Jira)" <ji...@apache.org> on 2023/10/12 10:50:00 UTC

[jira] [Commented] (HBASE-28138) Make the connection idle timeout configurable for the embedded HTTP servers

    [ https://issues.apache.org/jira/browse/HBASE-28138?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17774427#comment-17774427 ] 

Duo Zhang commented on HBASE-28138:
-----------------------------------

This can not be applied to other branches?

> Make the connection idle timeout configurable for the embedded HTTP servers
> ---------------------------------------------------------------------------
>
>                 Key: HBASE-28138
>                 URL: https://issues.apache.org/jira/browse/HBASE-28138
>             Project: HBase
>          Issue Type: Improvement
>    Affects Versions: 3.0.0-alpha-4
>            Reporter: qiuwei
>            Assignee: qiuwei
>            Priority: Minor
>             Fix For: 4.0.0-alpha-1
>
>         Attachments: 0001-HBASE-28138-Slow-HTTP-Denial-of-Service-Attack-of-HB.patch
>
>
> The Jetty Server may be slow HTTP denial of service attacks in hbase master web ui due to the default value of jetty connector idle timeout is 30000. This may cause such an attack.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)