spark-dgraph-connector icon indicating copy to clipboard operation
spark-dgraph-connector copied to clipboard

Wide node schema allows arbitrary column name injection

Open EnricoMi opened this issue 4 years ago • 0 comments

The wide node table schema uses predicate names as columns, allowing injection of arbitrary strings into column names. This should be reviewed and guarded against.

For instance, a predicate subject would conflict with the first column subject providing the uid of the row.

EnricoMi avatar Jun 15 '20 10:06 EnricoMi