Skip to content

[v18] fix: sanitize URL when fetching azure attested data intermediate cert#62406

Merged
nklaassen merged 1 commit intobranch/v18from
bot/backport-62158-branch/v18
Dec 19, 2025
Merged

[v18] fix: sanitize URL when fetching azure attested data intermediate cert#62406
nklaassen merged 1 commit intobranch/v18from
bot/backport-62158-branch/v18

Conversation

@nklaassen
Copy link
Copy Markdown
Contributor

@nklaassen nklaassen commented Dec 19, 2025

Backport #62158 to branch/v18

Manual Test Plan

  • invalid issuing certificate URLs are rejected
  • azure join method still works for agents using legacy join method

changelog: Fixed a potential SSRF vulnerability in the Azure join method implementation

@nklaassen nklaassen enabled auto-merge December 19, 2025 19:36
@nklaassen nklaassen added this pull request to the merge queue Dec 19, 2025
Merged via the queue into branch/v18 with commit 7fe1efd Dec 19, 2025
43 checks passed
@nklaassen nklaassen deleted the bot/backport-62158-branch/v18 branch December 19, 2025 20:13
@aadc-dev aadc-dev mentioned this pull request Dec 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants