Posted by akendo () akendo eu on Nov 07
Thank you for sharing this. I wondered how big the impact of this vulnerability is when you have only the ability to
access runs via the Kubernetes API? Would you argue that the vulnerability becomes harder (or impossible?) to exploit
when you can only interact with the service via another API?
In my current understanding of the vulnerabilities, it seems like you need to be able to interact with runs directly.
Furthermore, the ability to…
– Read More – Full Disclosure


