GP-6832 Resolved various Ghidra Server security concerns

This commit is contained in:
ghidra1
2026-05-14 14:47:25 -04:00
parent 7e89d94e34
commit be95b7d4ed
10 changed files with 129 additions and 72 deletions

View File

@@ -4,9 +4,9 @@
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
*
* http://www.apache.org/licenses/LICENSE-2.0
*
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
@@ -101,7 +101,8 @@ public class SystemUtilities {
/**
* Clean the specified user name to eliminate any spaces or leading domain name
* which may be present (e.g., "MyDomain\John Doe" becomes "JohnDoe").
* which may be present (e.g., "MyDomain\John Doe" becomes "JohnDoe"). Treat '/' in
* a similar fashion.
* @param name user name string to be cleaned-up
* @return the clean user name
*/
@@ -118,11 +119,15 @@ public class SystemUtilities {
uname = nameBuf.toString();
}
// Remove leading Domain Name if present
// Remove leading Domain Name if present (treat / and \ in a similar fashion)
int slashIndex = uname.lastIndexOf('\\');
if (slashIndex >= 0) {
uname = uname.substring(slashIndex + 1);
}
slashIndex = uname.lastIndexOf('/');
if (slashIndex >= 0) {
uname = uname.substring(slashIndex + 1);
}
return uname;
}