CVE-2020-17517: Apache Ozone: Ozone S3 Gateway allows bucket and key access to non authenticated users

2021-04-26 Thread Bharat Viswanadham
Description: The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl command or an unauthenticated HTTP request. This enables unauthorized access to buckets and

Re: [ANNOUNCE] Apache Hadoop Ozone 1.1.0 release

2021-04-26 Thread Prashant Pogde
Yes, the link is broken. I made the checkins as suggested by Marton/Attila to include the docs in the ozone-site. Something is broken in infra. Regards, Prashant > On Apr 26, 2021, at 10:53 AM, Bharat Viswanadham > wrote: > > Hi, > https://ozone.apache.org/docs/1.1.0 link returns 404. > Pra

Re: [ANNOUNCE] Apache Hadoop Ozone 1.1.0 release

2021-04-26 Thread Bharat Viswanadham
Hi, https://ozone.apache.org/docs/1.1.0 link returns 404. Prashant, are you still working on this to make it available? As currently 1.1.0 documentation cannot be seen? Thanks, Bharat On Thu, Apr 22, 2021 at 8:55 AM Wei-Chiu Chuang wrote: > I reverted the change in the Hadoop website. Will go