Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-32976

OSSO: prefer an explicit list of verbs instead of *

XMLWordPrintable

    • No
    • False
    • Hide

      None

      Show
      None

      Description of problem:

      The security recommendation is to replace every '*' with an explicit list of verbs instead. There are some places in https://github.com/openshift/secondary-scheduler-operator/blob/master/manifests/cluster-secondary-scheduler-operator.clusterserviceversion.yaml#L98 which uses '*'.
      

      Version-Release number of selected component (if applicable):

      All
      

      How reproducible:

      Always
      

      Steps to Reproduce:

      
      

      Actual results:

      OSSO rbac contains '*' as a verb
      
      

      Expected results:

      OSSO rbac does not contain '*' as a verb
      

      Additional info:

      
      

            aos-workloads-staff Workloads Team Bot Account
            jchaloup@redhat.com Jan Chaloupka
            Rama Kasturi Narra Rama Kasturi Narra
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated: