Skip to content

Effect of having Nodes/Proxy GET Permission in node-feature-discovery clusterrole #2074

@dttung2905

Description

@dttung2905

Describe the bug

Hi team, There has been an article posted online about how such permission can lead to potential RCE
https://grahamhelton.com/blog/nodes-proxy-rce
I found that we do have such permission here

Is it safe to just delete this permission without affecting the current functionality of NFD?
If it is safe to do so, I can follow up with a PR to delete it

To Reproduce

Expected behavior

Environment (please provide the following information):

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions