[
https://issues.apache.org/jira/browse/FLINK-40448?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
ASF GitHub Bot updated FLINK-40448:
-----------------------------------
Labels: pull-request-available (was: )
> Pin resolved address during operator artifact fetch to prevent DNS rebinding
> ----------------------------------------------------------------------------
>
> Key: FLINK-40448
> URL: https://issues.apache.org/jira/browse/FLINK-40448
> Project: Flink
> Issue Type: Improvement
> Components: Kubernetes Operator
> Reporter: Purushottam Sinha
> Priority: Minor
> Labels: pull-request-available
>
> As a follow-up to FLINK-40402, the operator validates a FlinkSessionJob
> jarURI host against the restricted-host policy, but the subsequent HTTP fetch
> resolves the hostname again when opening the connection — so a hostname that
> passes validation can resolve to a different (e.g. internal) address at
> connect time. This hardens the fetch to resolve the host once and connect to
> that same resolved address for each redirect hop, preserving the original
> hostname for the Host header and TLS SNI/certificate verification. Behavior
> is unchanged for well-behaved hosts.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)