Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-32976

OSSO: prefer an explicit list of verbs instead of *

XMLWordPrintable

    • No
    • 1
    • Workloads Sprint 254, Workloads Sprint 255
    • 2
    • False
    • Hide

      None

      Show
      None

      Description of problem:

      The security recommendation is to replace every '*' with an explicit list of verbs instead. There are some places in https://github.com/openshift/secondary-scheduler-operator/blob/master/manifests/cluster-secondary-scheduler-operator.clusterserviceversion.yaml#L98 which uses '*'.
      

      Version-Release number of selected component (if applicable):

      All
      

      How reproducible:

      Always
      

      Steps to Reproduce:

      
      

      Actual results:

      OSSO rbac contains '*' as a verb
      
      

      Expected results:

      OSSO rbac does not contain '*' as a verb
      

      Additional info:

      
      

              rh-ee-akramar Anya Kramar
              jchaloup@redhat.com Jan Chaloupka
              Rama Kasturi Narra Rama Kasturi Narra
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: