kubereboot / kured

Kubernetes Reboot Daemon
https://kured.dev
Apache License 2.0
2.11k stars 200 forks source link

A security vulnerability may cause whole cluster been hijacked #951

Open kaaass opened 3 days ago

kaaass commented 3 days ago

Hi community! I found a vulnerability in kured and reported it privately with respect to the security policy one week ago. I tried to send an email to the security mailing list, but I haven't received any response currently. This is not urging, I just wanted to ask if I haven't been successful in getting in touch with the maintainer (e.g. maybe the email is recognized as spam). I apologize if this issue has caused any trouble.