Skip to content

Bug: Security vulnerabilities in devtron #6839

@012git012

Description

@012git012

📜 Description

Hello @prakash100198 @vikramdevtron

Our team previously reached out to you regarding the vulnerabilities in devtron that we reported (#6796).

Thank you again for remediating these vulnerabilities.

Please review our comments in the corresponding advisories. The researcher believes that one of these vulnerabilities may still be reproducible, so we kindly ask you to check it.

We would also appreciate it if you could share your planned timeline for disclosure. Additionally, we ask you to register CVEs and publish the advisories.

Thank you for your cooperation.

👟 Reproduction steps

👍 Expected behavior

👎 Actual Behavior

☸ Kubernetes version

Cloud provider

🌍 Browser

Chrome

🧱 Your Environment

No response

✅ Proposed Solution

No response

👀 Have you spent some time to check if this issue has been raised before?

  • I checked and didn't find any similar issue

🏢 Have you read the Code of Conduct?

Metadata

Metadata

Labels

bugSomething isn't workingneeds-triageIssue is not approved or ready-to-work on

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions