generated from kubernetes/kubernetes-template-project
-
Notifications
You must be signed in to change notification settings - Fork 73
Open
Labels
help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.sig/securityCategorizes an issue or PR as relevant to SIG Security.Categorizes an issue or PR as relevant to SIG Security.triage/acceptedIndicates an issue or PR is ready to be actively worked on.Indicates an issue or PR is ready to be actively worked on.
Description
A common type of issue reported to the Security Response Committe under the Kubernetes bug bounty program is netlify takeovers. These occur when a Kubernetes DNS record points to a Netlify account that does not exist, and allow anyone to publish web content under a Kubernetes-project hostname.
We could help the project and the user community to be safer by doing proactive scanning for these sorts of issues.
I have discussed this idea with other SRC members, and we would like to ask the SIG Security Tooling community to help make it happen.
4rivappa
Metadata
Metadata
Assignees
Labels
help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.sig/securityCategorizes an issue or PR as relevant to SIG Security.Categorizes an issue or PR as relevant to SIG Security.triage/acceptedIndicates an issue or PR is ready to be actively worked on.Indicates an issue or PR is ready to be actively worked on.