halo-comment icon indicating copy to clipboard operation
halo-comment copied to clipboard

Security fix for ReDoS

Open ready-research opened this issue 2 years ago • 3 comments

Fixed Regular Expression Denial of Service vulnerability in URL validation.

Reported in huntr https://www.huntr.dev/bounties/395edb43-4ef5-4582-b22d-3abbecfbcc14/ Please Confirm the fix once it's merged. Thanks.

ready-research avatar Jun 09 '22 04:06 ready-research

@ready-research: Adding the "do-not-merge/release-note-label-needed" label because no release-note block was detected, please follow our release note process to remove it.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

f2c-ci-robot[bot] avatar Jun 09 '22 04:06 f2c-ci-robot[bot]

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment Approvers can cancel approval by writing /approve cancel in a comment

f2c-ci-robot[bot] avatar Jun 09 '22 04:06 f2c-ci-robot[bot]

/cc @halo-dev/sig-halo

JohnNiang avatar Jul 12 '22 06:07 JohnNiang