Robert Metzger created FLINK-40884:
--------------------------------------

             Summary: Flink configuration breaks when Keystore or Truststore 
passwords contain specific characters
                 Key: FLINK-40884
                 URL: https://issues.apache.org/jira/browse/FLINK-40884
             Project: Flink
          Issue Type: Bug
          Components: Runtime / RPC
            Reporter: Robert Metzger


Flink configuration breaks when Keystore or Truststore passwords contain 
specific characters, namely ” and \. 

Code: 
[https://github.com/apache/flink/blob/master/flink-rpc/flink-rpc-akka/src/main/java/org/apache/flink/runtime/rpc/pekko/PekkoUtils.java#L364-L390]

The sslKeyStorePassword and sslTrustStorePassword strings are injected into the 
ConfigBuilder object, wrapped by the general \”” and ”\”” string concatenizers 
(?). When the password contains either a quote or forward slash, the basic 
string parsing aggressively completes the otherwise successfully-escaped config 
string and blows up with errors – even leaking the initial parts of the 
password prior to the offending characters.

 



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to