You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
During pen-testing the following issue was identified:
During testing, Synopsys observed that the eks.privileged PodSecurityPolicy was implemented cluster-wide. This functionally "flattens" the cluster from an authorization perspective, removing the potential to limit operational privileges for deployed (and/or compromised) workloads running atop the cluster.
This in turn makes it trivial to perform potentially dangerous operations such as attempting to deploy privileged containers, access secrets, host resources, and other resources within the cluster (and potentially underlying cloud infrastructure).
During pen-testing the following issue was identified:
This issue is kept here for reference only. There is no intention to fix this right now. Please see the statement about the security profile of these deployment charts. https://github.com/bit-broker/charts/blob/main/INFO.md#security-profile
The text was updated successfully, but these errors were encountered: