Uploaded image for project: 'Hadoop YARN'
  1. Hadoop YARN
  2. YARN-10824

Title not set for JHS and NM webpages

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 3.4.0, 2.10.2, 3.3.2
    • 3.4.0, 2.10.2, 3.2.3, 3.3.2
    • nodemanager
    • None

    Description

      The following issue was reported by one of our internal web security check tools: 

      Passing a title to the jobHistoryServer(jhs) or Nodemanager(nm) pages using a url similar to:

      [https://[hostname]:[jhs_port]/jobhistory/about?title=12345%27%22]

      or 

      [https://[hostname]:[nm_port]/node?title=12345]

      sets the page title to be set to the value mentioned.

      [Image attached]

      Attachments

        1. JHS URL.jpg
          39 kB
          Rajshree Mishra
        2. NM URL.jpg
          42 kB
          Rajshree Mishra
        3. YARN-10824.001.patch
          2 kB
          Bilwa S T
        4. YARN-10824.002.patch
          2 kB
          Bilwa S T

        Activity

          People

            BilwaST Bilwa S T
            Rajshree Rajshree Mishra
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: