Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make script-based checks opt-in, like consul exec support #3087

Closed
slackpad opened this issue May 30, 2017 · 0 comments
Closed

Make script-based checks opt-in, like consul exec support #3087

slackpad opened this issue May 30, 2017 · 0 comments
Labels
theme/operator-usability Replaces UX. Anything related to making things easier for the practitioner type/enhancement Proposed improvement or new feature

Comments

@slackpad
Copy link
Contributor

As pointed out in http://www.kernelpicnic.net/2017/05/29/Pivoting-from-blind-SSRF-to-RCE-with-Hashicorp-Consul.html, and the resulting thread https://twitter.com/armon/status/869247551232385024, we should make enabling script checks opt-in given the power that's available there. With documentation we can tie enabling these into also enabling ACLs, which are already set up to prevent abuse if they are properly configured.

@slackpad slackpad added type/enhancement Proposed improvement or new feature security theme/operator-usability Replaces UX. Anything related to making things easier for the practitioner labels May 30, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
theme/operator-usability Replaces UX. Anything related to making things easier for the practitioner type/enhancement Proposed improvement or new feature
Projects
None yet
Development

No branches or pull requests

1 participant