Description
DefaultTopologyService#deployTopology does not validate the topology's name to prevent the creation of files outside the location or intent of the API. The name could be something like ../gateway-site, which could be used to overwrite the gateway configuration.
(e.g., KNOX_HOME/conf/topologies/../gateway-site.xml)