Breaking Changes
- CVE: Privilege Escalation via Session Policy Bypass (GHSA-jjjj-jwhf-8rgr) — affects Service Accounts and STS; upgrade immediately
Fixes
- LDAP TLS handshake now works with StartTLS and
tls_skip_verify=off - Incorrect poolID assignment after decommissioning pools
- Rebalance stats no longer empty after cancel operation
- AWS S3 POST policies now accept trailing slash...