Skip to content

Conversation

rtrivedi12
Copy link
Contributor

What changes were proposed in this pull request?

  1. Restricting temporary or permanent function creation with Blacklisted UDFs
  2. Changing Default blacklisted UDFs to include reflect, in_file, java_method functions

Why are the changes needed?

These functions using blacklisted udfs can be exploited; a security hole

Does this PR introduce any user-facing change?

Yes, the User will see Semantic Exception and function creation will fail using blacklisted UDF class

How was this patch tested?

Manually

Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants