Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Fix: Add IP validation in MachineRegistryController for security #40

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

yannaingtun
Copy link

Description
This PR adds proper IP address validation in the MachineRegistryController to prevent potential security issues related to malformed IP inputs.
The fix was implemented in the original Alibaba Sentinel repository in commit d4ea89e.

Changes:
Added validation to ensure IP inputs are valid IPv4 or IPv6 addresses
Uses IPAddressUtil to perform proper format validation
Rejects any malformed IP addresses before they can be processed

Without this validation, the application accepts any string as an IP address, which could lead to unexpected behavior or security vulnerabilities downstream.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant