CVE: RBAC Roles for etcd
created by Kamaji are not disjunct
#539
prometherion
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Publicly sharing a CVE in which all versions of Kamaji are affected: GHSA-6r4j-4rjc-8vw5
This CVE affects all installations with the following conditions:
etcd
etcd
certificates to spin up a connection to the Datastore and potentially extract the other Tenants' nameAlthough the perimeter of the CVE is pretty narrow we ranked the CVE as HIGH.
CLASTIX is the company maintaining and keeping Kamaji Open Source: since v1.0.0 we don't offer any more stable release artefacts. If you're running in production we strongly suggest you consider buying a commercial license which provides:
You can learn more from CLASTIX website support page
Beta Was this translation helpful? Give feedback.
All reactions