Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security point: Anonymous user has RoleBinding #404

Open
matthieu-robin opened this issue Oct 8, 2024 · 2 comments
Open

Security point: Anonymous user has RoleBinding #404

matthieu-robin opened this issue Oct 8, 2024 · 2 comments

Comments

@matthieu-robin
Copy link

After a kubescape scan, we have detected that Anonymous user has RoleBinding.
Should be more secure to close it.
Thanks

@gecube
Copy link
Collaborator

gecube commented Oct 9, 2024

@matthieu-robin Hi! Please provide more detailed report from kubescape. It does sound like a critical vulnerability, but we will look what we can do with it. Also it is not clear about which cluster you are talking about - main (based on talos) or tenant ones.

@matthieu-robin
Copy link
Author

Hi, here is the full report of Kubescape based on the version 0.16.2 of Cozystack ( Talos version 1.7.1).
The command used: kubescape scan -v -e tenant-ssl-jluc,opencost,neuvector,tenant-matthieu --format html --output results.html
results.html.zip

Let me know if you need more help on this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants