[
https://issues.apache.org/jira/browse/KNOX-2643?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Sandor Molnar updated KNOX-2643:
--------------------------------
+Apache Knox 3.0.0 release preparation+
We are about to cut the 3.0.0 release branch. master will move on to 3.1.0.
This issue is currently unresolved and is not automatically included in 3.0.0.
Please choose one of the following:
# If this belongs in 3.0.0: once the branch is cut, cherry-pick your commit(s)
onto the new v3.0.0 branch in addition to master. Leave Fix Version = 3.0.0 so
we can track it.
# Do nothing: we will move this issue to the next release (3.1.0) as part of
release cleanup.
If we don't hear back and see no cherry-pick, the issue will be re-targeted to
3.1.0. Thanks!
> TopologyService should validate descriptor and provider config file paths
> -------------------------------------------------------------------------
>
> Key: KNOX-2643
> URL: https://issues.apache.org/jira/browse/KNOX-2643
> Project: Apache Knox
> Issue Type: Bug
> Components: Server
> Affects Versions: 1.5.0
> Reporter: Philip Zampino
> Priority: Major
> Fix For: 3.0.0
>
>
> DefaultTopologyService#deployProviderConfiguration andÂ
> DefaultTopologyService#deployDescriptor blindly trust the file name without
> validating that the location will be bound to the expected resource directory
> (e.g., sharedProvidersDirectory, descriptorsDirectory).
> Names that would place the file outside the expected location or intent
> (e.g., ../gateway-site.xml) should be rejected.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)