Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

A security vulnerability may cause whole cluster been hijacked #1796

Open
kaaass opened this issue Jul 4, 2024 · 2 comments
Open

A security vulnerability may cause whole cluster been hijacked #1796

kaaass opened this issue Jul 4, 2024 · 2 comments
Labels
bug Something isn't working

Comments

@kaaass
Copy link

kaaass commented Jul 4, 2024

Hi community! I found a vulnerability in kubearmor and reported it privately with respect to the security policy one week ago. I tried to send an email to the security mailing list and some active maintainers, but I haven't received any response currently. This is not urging, I just wanted to ask if I haven't been successful in getting in touch with the maintainer (e.g. maybe the email is recognized as spam). I apologize if this issue has caused any trouble.

@kaaass kaaass added the bug Something isn't working label Jul 4, 2024
@DelusionalOptimist
Copy link
Member

Hey @kaaass, thanks for the detailed analysis over e-mail as well as the gentle reminder here. We've tried to give some explanations for your analysis. Also, as I mentioned some of these have been implemented/are being tracked as part of #1186 already.
Would love to further hear your thoughts on the same. Thanks.
cc @daemon1024

@kaaass
Copy link
Author

kaaass commented Jul 6, 2024

@DelusionalOptimist Thank you for the reply and analysis! I received the e-mail and just replied. I believe some of the risks can be eliminated through them, but the critical part is still not mitigated. I think we could continue to discuss this privately.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants