ZOOKEEPER-3731: Disallow HTTP TRACE method on PrometheusMetrics Server
This is a copy of https://github.com/apache/zookeeper/pull/1349/files (ZOOKEEPER-3772) but for the PrometheusMetrics Server.
Added the test requested in https://github.com/apache/zookeeper/pull/1539
Hi @hanm and @eolivelli Can you take a look at this PR? The metrics endpoint is hit on a nessus scan because it allows trace method. This has been fixed in this PR.
Hi @hanm and @eolivelli
Are there any further concerns about this PR? Or could this be merged?
Hi @hanm @eolivelli any news about this PR?
We are having issues with our vulnerabilities scans about this... I see this PR is opened for some time now, is there anything left to be merged?
Thanks