Skip to content

Conversation

rluvaton
Copy link

@linux-foundation-easycla
Copy link

linux-foundation-easycla bot commented Nov 16, 2022

CLA Signed

The committers listed above are authorized under a signed CLA.

@k8s-ci-robot k8s-ci-robot added the cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. label Nov 16, 2022
@k8s-ci-robot
Copy link
Contributor

Welcome @rluvaton!

It looks like this is your first PR to kubernetes-client/javascript 🎉. Please refer to our pull request process documentation to help your PR have a smooth ride to approval.

You will be prompted by a bot to use commands during the review process. Do not be afraid to follow the prompts! It is okay to experiment. Here is the bot commands documentation.

You can also check if kubernetes-client/javascript has its own contribution guidelines.

You may want to refer to our testing guide if you run into trouble with your tests not passing.

If you are having difficulty getting your pull request seen, please follow the recommended escalation practices. Also, for tips and tricks in the contribution process you may want to read the Kubernetes contributor cheat sheet. We want to make sure your contribution gets all the attention it needs!

Thank you, and welcome to Kubernetes. 😃

@k8s-ci-robot k8s-ci-robot added size/M Denotes a PR that changes 30-99 lines, ignoring generated files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. and removed cncf-cla: no Indicates the PR's author has not signed the CNCF CLA. labels Nov 16, 2022
@brendandburns
Copy link
Contributor

Thanks for the PR. fwiw, I wouldn't classify this as an RCE, since this requires a user to explicitly load a configuration either from disk or from some other input. In such circumstances, users should be expected to sanity check their input before handing it over to the library.

Obviously from a defense in depth perspective it is worth fixing this and no one should expect that embedding Javascript into their JSONPath should work in a kubeconfig, so I'm onboard with merging this PR. But it's definitely not an RCE since there is nothing 'remote' about this particular library call. (I'm not even sure that it is a vulnerability, since it requires the user of the library to knowingly supply malicious input)

@rluvaton
Copy link
Author

to be honest after I found that issue I looked at the top most packages that use that and fixed that in them to have better security in our ecosystem

The RCE was meant to be in the package itself (even though it's a feature)...

@rluvaton rluvaton requested review from brendandburns and removed request for drubin November 16, 2022 20:16
@brendandburns
Copy link
Contributor

/lgtm
/approve

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Nov 17, 2022
@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: brendandburns, rluvaton

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Nov 17, 2022
@k8s-ci-robot k8s-ci-robot merged commit 73211f7 into kubernetes-client:master Nov 17, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants