Skip to content

[v17] fix: sanitize URL when fetching azure attested data intermediate cert#62420

Merged
nklaassen merged 1 commit intobranch/v17from
nklaassen/v17/azure-fix
Dec 22, 2025
Merged

[v17] fix: sanitize URL when fetching azure attested data intermediate cert#62420
nklaassen merged 1 commit intobranch/v17from
nklaassen/v17/azure-fix

Conversation

@nklaassen
Copy link
Copy Markdown
Contributor

@nklaassen nklaassen commented Dec 20, 2025

Backport #62158 to branch/v17

Manual Test Plan

  • invalid issuing certificate URLs are rejected
  • azure join method still works for agents using legacy join method

changelog: Fixed a potential SSRF vulnerability in the Azure join method implementation

@nklaassen nklaassen enabled auto-merge December 22, 2025 18:27
@nklaassen nklaassen added this pull request to the merge queue Dec 22, 2025
Merged via the queue into branch/v17 with commit 1c583ab Dec 22, 2025
44 of 45 checks passed
@nklaassen nklaassen deleted the nklaassen/v17/azure-fix branch December 22, 2025 18:51
@fheinecke fheinecke mentioned this pull request Jan 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants