Actions
Bug #5907
closedUser story #6363: Secure agent/server communication
Any user can forge a fake report
Pull Request:
Severity:
Critical - prevents main use of Rudder | no workaround | data loss | security
UX impact:
User visibility:
First impressions of Rudder
Effort required:
Large
Priority:
0
Name check:
Fix check:
Regression:
Description
This is a vulnerability.
Any user can write to syslog.
Therefore, any user can create a fake report telling rudder there is a problem (or there is no problem).
Actions