knative-extensions / security-guard

Runtime security plug to protect user containers

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Ada Logics Security Review - Tag-Security Sponsored

davidhadas opened this issue · comments

Ada Logics Security Review identified a number of issues with security-guard:

ADA-KNATIVE-23-5 - profiling endpoints need to be removed
ADA-KNATIVE-23-6 - endpoints need to be protect against slowloris - by adding ReadHeaderTimeout
ADA-KNATIVE-23-12 - text needed to point out how vulnerabilities are notified - Need to add Security.md
ADA-KNATIVE-23-13,14 Reject requests with too large body at endpoints to avoid crash