-
Bug
-
Resolution: Done-Errata
-
Normal
-
None
-
None
-
2
-
False
-
-
False
-
?
-
?
-
octavia-operator-container-1.0.4-4
-
?
-
?
-
None
-
-
-
Important
SAST reports:
Error: SIGMA.container_storing_secret_in_environment_variable (CWE-526):
unpacked_remote_sources/app/tests/kuttl/common/assert_sample_deployment.yaml:159: Sigma main event: The Kubernetes container stores secrets in environment variables, which could be leaked if the environment is logged.
unpacked_remote_sources/app/tests/kuttl/common/assert_sample_deployment.yaml:159: remediation: Provide access to secrets via volume mounts instead of setting `valueFrom.secretKeyRef` in `env`.
secrets should not be passed in env vars
- links to
-
RHSA-2024:140345 RHOSO OpenStack Podified operator containers security update