Skip to content

Conversation

yannaingtun
Copy link

Description
This PR adds proper IP address validation in the MachineRegistryController to prevent potential security issues related to malformed IP inputs.
The fix was implemented in the original Alibaba Sentinel repository in commit d4ea89e.

Changes:
Added validation to ensure IP inputs are valid IPv4 or IPv6 addresses
Uses IPAddressUtil to perform proper format validation
Rejects any malformed IP addresses before they can be processed

Without this validation, the application accepts any string as an IP address, which could lead to unexpected behavior or security vulnerabilities downstream.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant