hanicz opened a new pull request, #1352: URL: https://github.com/apache/knox/pull/1352
[KNOX-3188](https://issues.apache.org/jira/browse/KNOX-3188) - Add group-based configuration parameter for KnoxToken renewer/revoker access control [KNOX-3410](https://issues.apache.org/jira/browse/KNOX-3410) - KnoxToken enable/disable endpoints perform no caller authorization [KNOX-3411](https://issues.apache.org/jira/browse/KNOX-3411) - KnoxToken getUserTokens returns every user's token metadata without a caller authorization check [KNOX-3413](https://issues.apache.org/jira/browse/KNOX-3413) - KnoxToken passcode verification accepts a valid passcode for a different token [KNOX-3416](https://issues.apache.org/jira/browse/KNOX-3416) - KnoxSSO redirects to untrusted site [KNOX-3417](https://issues.apache.org/jira/browse/KNOX-3417) - A short description of the change [KNOX-3418](https://issues.apache.org/jira/browse/KNOX-3418) - Path traversal → arbitrary file write/overwrite in the Apache Knox Admin API ## What changes were proposed in this pull request? Backporting security fixes ## How was this patch tested? Did the same tested as specified in the parent PRs. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
