- Jan 06, 2024
-
-
Sheogorath authored
This patch should help to make sure, that nothing uses plaintext signatures.
-
Sheogorath authored
-
- Jan 04, 2024
-
-
Sheogorath authored
This patch fixes the usage of oauth2-proxy by already triggering auth on the GET instead of the POST request.
-
Sheogorath authored
-
- Jan 02, 2024
-
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
- Jan 01, 2024
-
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
- Dec 31, 2023
-
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
-
Sheogorath authored
The usage of the trusted-ip config resulted in a security incident that allowed access to any oauth2-proxy protected endpoint without requiring authentication. Thankfully all significant endpoints had been protected by additional measures such as network restrictions and are therefore not affected. Only the prometheus and alertmanager endpoints have been exposed to the public internet, but are not exposing sensitive data beyond metrics. A check of the relevant logs didn't provide any indication of compromise.
-
Sheogorath authored
-
Sheogorath authored