Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG]: Rate limiting Vulnerability #2480

Closed
1 task done
rook1337 opened this issue Feb 29, 2024 · 1 comment
Closed
1 task done

[BUG]: Rate limiting Vulnerability #2480

rook1337 opened this issue Feb 29, 2024 · 1 comment
Labels
bug Something isn't working

Comments

@rook1337
Copy link

Contact Details [Optional]

No response

System Information

Linux

What happened?

Hello team,
Please check here for full detailed report:- https://huntr.com/bounties/0674977f-5fd0-4af6-b4d1-40186a6a4da7/

Reproduction steps

...

Relevant log output

No response

Code of Conduct

  • I agree to follow this project's Code of Conduct
@rook1337 rook1337 added the bug Something isn't working label Feb 29, 2024
@stefannica
Copy link
Contributor

As explained in the attached report, the ZenML built-in username + password authentication scheme is not meant to be used in production environments. For production settings, ZenML needs to be hooked up to an external authenticator that takes on the responsibilities of implementing more secure authentication schemes and enforcing best security practices like rate limiting, password strength and expiration etc.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants