Skip to content

chore: add file size limits to object store downloads#12924

Draft
alyssacgoins wants to merge 2 commits intokubeflow:masterfrom
alyssacgoins:ada-kubefl-04-fix
Draft

chore: add file size limits to object store downloads#12924
alyssacgoins wants to merge 2 commits intokubeflow:masterfrom
alyssacgoins:ada-kubefl-04-fix

Conversation

@alyssacgoins
Copy link
Contributor

Description of your changes:
Address Ada logistics security audit issue ADA-KUBEFL-04 object store read-all DoS, in which anyone with write permissions to the Minio ObjectStore can overwrite all objects and cause denial of service of the node whenever someone downloads any file in Kubeflow Pipelines.

Checklist:

@google-oss-prow
Copy link

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@google-oss-prow
Copy link

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign chensun for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Signed-off-by: Alyssa Goins <agoins@redhat.com>
Signed-off-by: Alyssa Goins <agoins@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant