Uploaded image for project: 'Hadoop Common'
  1. Hadoop Common
  2. HADOOP-19079

HttpExceptionUtils to check that loaded class is really an exception before instantiation

    XMLWordPrintableJSON

Details

    Description

      It can be dangerous taking class names as inputs from HTTP messages even if we control the source. Issue is in HttpExceptionUtils in hadoop-common (validateResponse method).

      I can provide a PR that will highlight the issue.

      Attachments

        Issue Links

          Activity

            People

              pj.fanning PJ Fanning
              fanningpj PJ Fanning
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: