Selected issues resolved in Cloudera Migration Assistant 4.1.1.
Cloudera Migration Assistant 4.1.1
- CMA-4453: Rate limiting on Auth Server OAuth2 token
endpoint
- 4.1.1
-
The OAuth2 token endpoint did not limit request rates, which could allow
denial-of-service against authentication. The gateway now rate-limits this
endpoint.
- CMA-4455: Security response headers (CSP, HSTS,
X-Frame-Options)
- 4.1.1
-
This release adds standard browser security headers for the CMA and gateway.
- CMA-4448: Dependency version lift for Spring Boot 4.0.7
(CVE)
- 4.1.1
-
Third-party library versions were upgraded to address critical and high severity
vulnerabilities reported in security scans, including Jackson, Netty, PostgreSQL JDBC,
and Bouncy Castle components.