apache / apache/arrow-java

[Java][FlightSQL][JDBC] Driver drops TLS for endpoint locations advertised by the server

Offen
#1,232 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Java
Sterne
94
Forks
152
Ø Merge
3 T. 16 Std.
Gemergte PRs (30 T.)
11

Beschreibung

When a query result has endpoints with non-empty locations, `ArrowFlightSqlClientHandler.getStreams` clones the connection's `Builder` and connects to each advertised location. The clone keeps `username`/`password`, `token` and the OAuth config, and encryption is then set from the location scheme alone:

```java
.withEncryption(endpointUri.getScheme().equals(LocationSchemes.GRPC_TLS))
```

So a location with any other scheme (`grpc+tcp://` in particular) turns encryption off for that endpoint client even when the connection was opened with `useEncryption=true`. `build()` then runs the handshake and sends the credentials over the plaintext channel to the advertised host.

The documented meaning of `useEncryption` (default `true`) is "Whether to use TLS (the default is an encrypted connection)", so a server-supplied string silently overriding it is surprising: a compromised or hostile Flight SQL server, or anything able to influence the `FlightInfo` it returns, can have the driver hand over the user's credentials in cleartext, and a passive attacker on the endpoint path can read them.

Reproduced against a handler built with `withEncryption(true)` plus a username/password, given a `FlightInfo` with one endpoint at `Location.forGrpcInsecure(...)`: the driver attempts the connection and reaches `ClientHandshakeWrapper` on the unencrypted channel instead of refusing it.

`arrow-flight-sql-jdbc-driver`, main.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne in ArrowFlightSqlClientHandler.getStreams und verfolge, wie beworbene Endpoint-Positionen geklonte Clients konfigurieren; untersuche ClientHandshakeWrapper für den beobachteten Handshake-Pfad. Reproduziere dies mit withEncryption(true), credentials und einem unsicheren FlightInfo-Endpoint und füge Regressionstests hinzu, die zeigen, dass die konfigurierte Verschlüsselungsanforderung nicht stillschweigend verloren geht und dass credentials nicht über Klartext gesendet werden.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
java
Bereich
security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Ruhig
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
72/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.