Hardening suggestions for Stirling-PDF / multipleFix (#1743)

Sandboxed URL creation to prevent SSRF attacks

Co-authored-by: pixeebot[bot] <104101892+pixeebot[bot]@users.noreply.github.com>
This commit is contained in:
pixeebot[bot]
2024-08-23 09:18:08 +01:00
committed by GitHub
parent c4efed87b4
commit fcc78089ad

View File

@@ -77,7 +77,7 @@ public class GeneralUtils {
public static boolean isURLReachable(String urlStr) {
try {
URL url = new URL(urlStr);
URL url = Urls.create(urlStr, Urls.HTTP_PROTOCOLS, HostValidator.DENY_COMMON_INFRASTRUCTURE_TARGETS);
HttpURLConnection connection = (HttpURLConnection) url.openConnection();
connection.setRequestMethod("HEAD");
int responseCode = connection.getResponseCode();