Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove some of the excessive permissions granted and fix the issue #3361 #3446

Closed
wants to merge 1 commit into from

Conversation

HouqiyuA
Copy link

Thanks for contributing!

What type of PR is this?

What this PR does / why we need it:
Remove some of the excessive permissions granted and fix the issue
Which issue(s) this PR fixes:
#3361

Fixes #3361#

Special notes for your reviewer:

Signed-off-by: houqiyu <qiyuhou2@gmail.com>
@cyclinder
Copy link
Collaborator

Hi @HouqiyuA Thanks for the PR! It looks like something is broken while you remove the permissions, Are you able to fix the CI failure? thank you so much for your attention and participation.

@HouqiyuA
Copy link
Author

HouqiyuA commented May 1, 2024 via email

@cyclinder
Copy link
Collaborator

I will close it if you don't want to keep working on this issue. @kaaass want to work on this.

Can spiderpool team reward our team after fixiing this problem? For
example, apply for a CVE ID to our team for this problem or other ways?

Sure, but I don't know how to apply for a CVE ID.

@cyclinder cyclinder closed this May 6, 2024
@kaaass
Copy link
Contributor

kaaass commented May 6, 2024

Sure, but I don't know how to apply for a CVE ID.

@cyclinder I can help this! I had DM you in Slack.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

A potential risk in spiderpool that could lead to takeover of the cluster
3 participants