Merge pull request #17024 from jmhbnz/backport-ssrf-fix

[3.5] Backport disable following redirects when checking peer urls
This commit is contained in:
Marek Siarkowicz 2023-11-28 21:22:32 +01:00 committed by GitHub
commit ce4ae2beb6
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -275,6 +275,9 @@ func isCompatibleWithVers(lg *zap.Logger, vers map[string]*version.Versions, loc
func getVersion(lg *zap.Logger, m *membership.Member, rt http.RoundTripper) (*version.Versions, error) {
cc := &http.Client{
Transport: rt,
CheckRedirect: func(req *http.Request, via []*http.Request) error {
return http.ErrUseLastResponse
},
}
var (
err error