[ 
https://issues.apache.org/jira/browse/FLINK-40448?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

ASF GitHub Bot updated FLINK-40448:
-----------------------------------
    Labels: pull-request-available  (was: )

> Pin resolved address during operator artifact fetch to prevent DNS rebinding
> ----------------------------------------------------------------------------
>
>                 Key: FLINK-40448
>                 URL: https://issues.apache.org/jira/browse/FLINK-40448
>             Project: Flink
>          Issue Type: Improvement
>          Components: Kubernetes Operator
>            Reporter: Purushottam Sinha
>            Priority: Minor
>              Labels: pull-request-available
>
> As a follow-up to FLINK-40402, the operator validates a FlinkSessionJob 
> jarURI host against the restricted-host policy, but the subsequent HTTP fetch 
> resolves the hostname again when opening the connection — so a hostname that 
> passes validation can resolve to a different (e.g. internal) address at 
> connect time. This hardens the fetch to resolve the host once and connect to 
> that same resolved address for each redirect hop, preserving the original 
> hostname for the Host header and TLS SNI/certificate verification. Behavior 
> is unchanged for well-behaved hosts. 



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to